Towards Scalable Cluster Auditing through Grammatical Inference over Provenance Graphs

Towards Scalable Cluster Auditing through Grammatical Inference over Provenance Graphs
复制标题

DOI:
10.14722/ndss.2018.23141
复制
发表时间:
2018
期刊:
--
影响因子:
--
通讯作者:
Wajih Ul Hassan;Mark Lemay;Nuraini Aguse;Adam Bates;Thomas Moyer
Wajih Ul Hassan;Mark Lemay;Nuraini Aguse;Adam Bates;Thomas Moyer
中科院分区:
其他
文献类型:
--
作者:
Wajih Ul Hassan;Mark Lemay;Nuraini Aguse;Adam Bates;Thomas Moyer

文献摘要

被引文献

相似文献

在大型分布式系统中调查系统入侵的性质仍然是一个众所周知的困难的挑战。虽然监控工具(例如,防火墙、IDS)通过易于使用的管理界面提供初步警报,攻击重建仍然需要管理员筛选数百台机器上本地存储的千兆字节的系统审计日志。目前,有两个基本障碍阻碍了系统层审计和现代集群监控工具之间的协同:1)数据中心生成的大量审计数据传输到中央节点的成本过高,以及2)系统层审计造成了“大海捞针”的问题,例如可能需要数百个员工小时来诊断单个入侵。本文介绍了Winnower,一个可扩展的系统,基于集群监控,解决这些挑战。我们的关键见解是,对于分布式应用程序中跨节点复制的任务,可以在审计日志上定义一个模型,以简洁地总结许多节点的行为,从而消除将冗余审计记录传输到中央监控节点的需要。具体来说,Winnower将审计记录解析为描述单个节点行为的起源图,然后使用确定性有限自动机(DFA)学习的新适应对单个图进行语法推理,以同时生成多个节点的行为模型。该起源模型可以有效地传输到中心节点,并用于识别集群中的异常事件。我们为Docker Swarm容器集群实现了Winnower,并评估了我们的系统对现实世界的应用程序和攻击。我们表明,Winnower大大减少了存储和网络开销与聚合系统审计日志,高达98%,而不牺牲攻击调查所需的重要信息。因此,Winnower代表了分布式系统中安全监控的重要一步。
Investigating the nature of system intrusions in large distributed systems remains a notoriously difficult challenge. While monitoring tools (e.g., Firewalls, IDS) provide preliminary alerts through easy-to-use administrative interfaces, attack reconstruction still requires that administrators sift through gigabytes of system audit logs stored locally on hundreds of machines. At present, two fundamental obstacles prevent synergy between system-layer auditing and modern cluster monitoring tools: 1) the sheer volume of audit data generated in a data center is prohibitively costly to transmit to a central node, and 2) systemlayer auditing poses a “needle-in-a-haystack” problem, such that hundreds of employee hours may be required to diagnose a single intrusion. This paper presents Winnower, a scalable system for auditbased cluster monitoring that addresses these challenges. Our key insight is that, for tasks that are replicated across nodes in a distributed application, a model can be defined over audit logs to succinctly summarize the behavior of many nodes, thus eliminating the need to transmit redundant audit records to a central monitoring node. Specifically, Winnower parses audit records into provenance graphs that describe the actions of individual nodes, then performs grammatical inference over individual graphs using a novel adaptation of Deterministic Finite Automata (DFA) Learning to produce a behavioral model of many nodes at once. This provenance model can be efficiently transmitted to a central node and used to identify anomalous events in the cluster. We implement Winnower for Docker Swarm container clusters and evaluate our system against real-world applications and attacks. We show that Winnower dramatically reduces storage and network overhead associated with aggregating system audit logs, by as much as 98%, without sacrificing the important information needed for attack investigation. Winnower thus represents a significant step forward for security monitoring in distributed systems.