vNIDS: Towards Elastic Security with Safe and Efficient Virtualization of Network Intrusion Detection Systems

vNIDS: Towards Elastic Security with Safe and Efficient Virtualization of Network Intrusion Detection Systems
复制标题

DOI:
10.1145/3243734.3243862
复制
发表时间:
2018-10
期刊:
Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Hongda Li;Hongxin Hu;G. Gu;Gail-Joon Ahn;Fuqiang Zhang
Hongda Li;Hongxin Hu;G. Gu;Gail-Joon Ahn;Fuqiang Zhang
中科院分区:
其他
文献类型:
--
作者:
Hongda Li;Hongxin Hu;G. Gu;Gail-Joon Ahn;Fuqiang Zhang

文献摘要

相似文献

传统网络入侵检测系统(NIDS)通常在通用性和灵活性较差的供应商专有设备或中间盒上实现。新兴的网络功能虚拟化(NFV)和软件定义网络(SDN)技术可以对NIDS进行虚拟化,并灵活地对其进行扩展以应对攻击流量的变化。然而,这种弹性特性绝不能以降低检测效果和高昂的配置成本为代价。在本文中,我们提出了一种创新的NIDS架构——vNIDS,以实现NIDS的安全高效虚拟化。vNIDS解决了在NIDS虚拟化过程中有关有效入侵检测和非单体式NIDS配置的两个关键挑战。前者通过检测状态共享来解决,同时将虚拟化环境中的共享开销降至最低。特别是,采用静态程序分析来确定哪些检测状态需要共享。vNIDS通过将虚拟NIDS配置为微服务并采用程序切片来划分检测逻辑程序,以便每个微服务可以分别执行,从而解决了后者的挑战。我们实现了vNIDS的一个原型来证明我们方法的可行性。我们的评估结果表明,vNIDS可以为NIDS虚拟化提供有效的入侵检测和高效的配置。
Traditional Network Intrusion Detection Systems (NIDSes) are generally implemented on vendor proprietary appliances or middleboxes with poor versatility and flexibility. Emerging Network Function Virtualization (NFV) and Software-Defined Networking (SDN) technologies can virtualize NIDSes and elastically scale them to deal with attack traffic variations. However, such an elasticity feature must not come at the cost of decreased detection effectiveness and expensive provisioning. In this paper, we propose an innovative NIDS architecture, vNIDS, to enable safe and efficient virtualization of NIDSes. vNIDS addresses two key challenges with respect to effective intrusion detection and non-monolithic NIDS provisioning in virtualizing NIDSes. The former challenge is addressed by detection state sharing while minimizing the sharing overhead in virtualized environments. In particular, static program analysis is employed to determine which detection states need to be shared. vNIDS addresses the latter challenge by provisioning virtual NIDSes as microservices and employing program slicing to partition the detection logic programs so that they can be executed by each microservice separately. We implement a prototype of vNIDS to demonstrate the feasibility of our approach. Our evaluation results show that vNIDS could offer both effective intrusion detection and efficient provisioning for NIDS virtualization.