ContainerGuard: A Real-Time Attack Detection System in Container-Based Big Data Platform

ContainerGuard: A Real-Time Attack Detection System in Container-Based Big Data Platform
复制标题

ContainerGuard:基于容器的大数据平台的实时攻击检测系统

DOI:
10.1109/tii.2020.3047416
复制
发表时间:
2022-05
影响因子:
12.3
通讯作者:
Ning Zhang
Ning Zhang
中科院分区:
计算机科学1区
文献类型:
--
作者:
Yulong Wang;Qixu Wang;Xingshu Chen;Dajiang Chen;Xiaojie Fang;Mingyong Yin;Ning Zhang

文献摘要

相似文献

容器作为一种轻量级、灵活、高性能的虚拟化操作系统,被用于加速大数据平台。然而,由于资源隔离机制的不完善和共享内核的特性,meltdown和spectre攻击会导致内核空间和驻留容器的信息泄露。本文提出了一种基于容器的大数据平台的抗噪实时检测系统ContainerGuard,用于检测熔毁攻击和幽灵攻击。ContainerGuard使用非侵入性的方式收集容器中进程的生命周期多变量时间序列性能事件数据,然后使用变分自编码器集成作为生成神经网络来学习正常模式的鲁棒表示。因此,ContainerGuard满足了基于容器的大数据平台对信息保护的迫切需求。我们使用真实数据集进行的评估表明,ContainerGuard实现了出色的检测性能,并且只给平台带来了大约4.5%的运行性能开销。
As a lightweight, flexible, and high-performance operating system virtualization, containers are used to speed up the big data platform. However, due to the imperfection of the resource isolation mechanism and the property of shared kernel, the meltdown and spectre attacks can lead to information leakage of kernel space and coresident containers. In this article, a noise-resilient and real-time detection system, named ContainerGuard, is proposed to detect meltdown and spectre attacks in the container-based big data platform. ContainerGuard uses a nonintrusive manner to collect lifecycle multivariate time-series performance event data of processes in containers and then uses ensemble of variational autoencoders as generative neural networks to learn the robust representations of normal patterns. Therefore, ContainerGuard meets the urgent need for information protection in the container-based big data platform. Our evaluations using real-world datasets show that ContainerGuard achieves excellent detection performance and only introduces about 4.5% of running performance overhead to the platform.