Resilient intrusion detection system for cloud containers

被引:9
|
作者
Abed, Amr S. [1 ]
Azab, Mohamed [2 ]
Clancy, Charles [3 ]
Kashkoush, Mona S. [2 ]
机构
[1] Virginia Tech, Dept Elect & Comp Engn, Blacksburg, VA 24061 USA
[2] City Sci Res & Technol Applicat, Informat Res Inst, Alexandria, Egypt
[3] Virginia Tech, Hume Ctr Natl Secur & Technol, Arlington, VA USA
关键词
cloud security; intrusion detection; behaviour modelling; resilience; Linux container; moving-target defence; MTD; VIRTUAL MACHINE MIGRATION; ATTACKS;
D O I
10.1504/IJCNDS.2020.103857
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The lightweight virtualisation and isolated execution offered by Linux containers qualify it to be the dominant virtualisation platform for cloud-based applications. The fact that Linux containers run on the same host while sharing the same kernel opens the door for new attacks. However, limited research has been conducted in the area of securing cloud containers. This paper presents a resilient intrusion detection and resolution system for cloud-based containers. The system relies on two main pillars, a real-time smart behaviour monitoring mechanism to detect maliciously behaving containers, and a moving-target defence approach that applies runtime container migration to quarantine such containers and to minimise attack dispersion. To avoid zero-day targeted attacks, the system also induces random live migrations between running containers to obfuscate its execution behaviour. Such obfuscation makes it harder for attackers to execute their targeted attacks. The system was tested by a big-data application using a container-based Apache Hadoop cluster to demonstrate the system's ability to automatically deploy, monitor, detect, and respond to maliciously behaving applications by live migration or by rolling back the container to a safe state. Results showed that the proposed system efficiently ensure safe and secure container operation.
引用
收藏
页码:1 / 22
页数:22
相关论文
共 50 条
  • [21] An Enhanced Resilient Backpropagation Artificial Neural Network for Intrusion Detection System
    Naoum, Reyadh Shaker
    Abid, Namh Abdula
    Al-Sultani, Zainab Namh
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2012, 12 (03): : 11 - 16
  • [22] An Enhanced Resilient Backpropagation Artificial Neural Network for Intrusion Detection System
    Naoum, Reyadh Shaker
    Abid, Namh Abdula
    Al-Sultani, Zainab Namh
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2013, 13 (03): : 98 - 104
  • [23] SoCINT: Resilient System-on-Chip via Dynamic Intrusion Detection
    Sayed-Ahmed, Amr
    Haj-Yahya, Jawad
    Chattopadhyay, Anupam
    2019 32ND INTERNATIONAL CONFERENCE ON VLSI DESIGN AND 2019 18TH INTERNATIONAL CONFERENCE ON EMBEDDED SYSTEMS (VLSID), 2019, : 359 - 364
  • [24] Cloud Security: LKM and Optimal Fuzzy System for Intrusion Detection in Cloud Environment
    Shyla, S. Immaculate
    Sujatha, S. S.
    JOURNAL OF INTELLIGENT SYSTEMS, 2020, 29 (01) : 1626 - 1642
  • [25] Hybrid Intrusion Detection System for Private Cloud: A Systematic Approach
    Rajendran, Praveen Kumar
    Muthukumar, B.
    Nagarajan, G.
    INTERNATIONAL CONFERENCE ON COMPUTER, COMMUNICATION AND CONVERGENCE (ICCC 2015), 2015, 48 : 325 - 329
  • [26] Efficacious Novel Intrusion Detection System for Cloud Computing Environment
    Rana, Pooja
    Batra, Isha
    Malik, Arun
    Ra, In-Ho
    Lee, Oh-Sung
    Hosen, A. S. M. Sanwar
    IEEE ACCESS, 2024, 12 : 99223 - 99239
  • [27] A Fingerprinting System Calls Approach for Intrusion Detection in a Cloud Environment
    Gupta, Sanchika
    Sardana, Anjali
    Kumar, Padam
    Abraham, Ajith
    2012 FOURTH INTERNATIONAL CONFERENCE ON COMPUTATIONAL ASPECTS OF SOCIAL NETWORKS (CASON), 2012, : 309 - 314
  • [28] The Research of Intrusion Detection System Based on ANN on Cloud Platform
    Jiang, Xuesong
    Wei, Xiumei
    Geng, Yushui
    INFORMATION TECHNOLOGY APPLICATIONS IN INDUSTRY, PTS 1-4, 2013, 263-266 : 2962 - 2965
  • [29] Integrated Intrusion Detection and Prevention System with Honeypot in Cloud Computing
    Ravji, Sajaan
    Ali, Maaruf
    2018 INTERNATIONAL CONFERENCE ON COMPUTING, ELECTRONICS & COMMUNICATIONS ENGINEERING (ICCECE), 2018, : 95 - 100
  • [30] An Improved Intrusion Detection System to Preserve Security in Cloud Environment
    Ghosh, Partha
    Biswas, Sumit
    Shakti, Shivam
    Phadikar, Santanu
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY AND PRIVACY, 2020, 14 (01) : 67 - 80