Intrusion Detection in the Cloud

被引:77
作者
Roschke, Sebastian [1 ]
Cheng, Feng [1 ]
Meinel, Christoph [1 ]
机构
[1] Univ Potsdam, HPI, D-14440 Potsdam, Germany
来源
EIGHTH IEEE INTERNATIONAL CONFERENCE ON DEPENDABLE, AUTONOMIC AND SECURE COMPUTING, PROCEEDINGS | 2009年
关键词
IDS; IDS Management; Cloud Computing; Virtualization; Virtual Machine;
D O I
10.1109/DASC.2009.94
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Intrusion Detection Systems (IDS) have been used widely to detect malicious behaviors in network communication and hosts. IDS management is an important capability for distributed IDS solutions, which makes it possible to integrate and handle different types of sensors or collect and synthesize alerts generated from multiple hosts located in the distributed environment. Facing new application scenarios in Cloud Computing, the IDS approaches yield several problems since the operator of the IDS should be the user, not the administrator of the Cloud infrastructure. Extensibility, efficient management, and compatibility to virtualization-based context need to be introduced into many existing IDS implementations. Additionally, the Cloud providers need to enable possibilities to deploy and configure IDS for the user. Within this paper, we summarize several requirements for deploying IDS in the Cloud and propose an extensible IDS architecture for being easily used in a distributed cloud infrastructure.
引用
收藏
页码:729 / 734
页数:6
相关论文
共 24 条
[1]  
[Anonymous], AM EL COMP CLOUD AM
[2]  
[Anonymous], Google app engine
[3]  
ANTIVIRUSORANTI.TH, 2009, ACCESSED OCT
[4]  
ARCHITECTUREFOR.JA, 2009, ACCESSED OCT
[5]  
Armbrust M., 2009, CLOUDS BERKLEY VIEW
[6]  
Cheng F, 2009, LECT NOTES COMPUT SC, V5451, P360, DOI 10.1007/978-3-642-00843-6_31
[7]  
DEBAR H, 2004, INTRUSION DETECTION
[8]  
*EICAR, ANT ANT TEST FIL
[9]  
F C, 2009, APRIL, V5451, P360
[10]  
*F SEC CORP, F SEC LIN SEC