ProvTalk: Towards Interpretable Multi-level Provenance Analysis in Networking Functions Virtualization (NFV)

ProvTalk: Towards Interpretable Multi-level Provenance Analysis in Networking Functions Virtualization (NFV)
复制标题

ProvTalk:网络功能虚拟化 (NFV) 中的可解释多级来源分析

DOI:
10.14722/ndss.2022.23103
复制
发表时间:
2022
期刊:
Proceedings 2022 Network and Distributed System Security Symposium
影响因子:
--
通讯作者:
Lingyu Wang
Lingyu Wang
中科院分区:
--
文献类型:
--
作者:
Azadeh Tabiban;Heyang Zhao;Yosr Jarraya;M. Pourzandi;Mengyuan Zhang;Lingyu Wang

文献摘要

参考文献

被引文献

相似文献

- 网络功能虚拟化(NFV)实现了在云之上敏捷部署网络服务。然而,由于NFV涉及表示相同组件的多个抽象级别,因此查明安全事件的根本原因可能变得具有挑战性。例如,安全事件可能在与其根本原因操作进行的不同级别被检测到,两者之间没有明显的联系。此外,由于NFV的固有复杂性,现有的来源分析技术可能产生对于人类分析师来说不切实际地大到无法解释的结果。在本文中,我们提出了ProvTalk,这是一个起源分析系统,可以处理NFV独特的多层次性质,并帮助分析师识别安全事件的根本原因。具体来说,我们首先定义一个多级起源模型来捕获NFV级别之间的依赖关系。接下来,我们通过三种新的技术来提高可解释性,即,多级修剪、基于挖掘的聚合和基于规则的自然语言翻译。我们在Tacker-OpenStack NFV平台上实现了ProvTalk,并基于真实的安全事件验证了其有效性。我们证明,ProvTalk捕获管理API调用发出的所有NFV服务,并产生更多的可解释的结果显着减少的起源图的大小(约3.6倍减少通过多级修剪方案和2倍减少通过聚合方案)。我们的用户研究表明,ProvTalk通过生成更多可解释的结果来促进现实世界用户的分析任务。
—Network functions virtualization (NFV) enables agile deployment of network services on top of clouds. However, as NFV involves multiple levels of abstraction representing the same components, pinpointing the root cause of security incidents can become challenging. For instance, a security incident may be detected at a different level from where its root cause operations were conducted with no obvious link between the two. Moreover, existing provenance analysis techniques may produce results that are impractically large for human analysts to interpret due to the inherent complexity of NFV. In this paper, we propose ProvTalk, a provenance analysis system that handles the unique multi-level nature of NFV and assists the analyst to identify the root cause of security incidents. Specifically, we first define a multi-level provenance model to capture the dependencies between NFV levels. Next, we improve the interpretability through three novel techniques, i.e., multi-level pruning, mining-based aggregation, and rule-based natural language translation. We implement ProvTalk on a Tacker-OpenStack NFV platform and validate its effectiveness based on real-world security incidents. We demonstrate that ProvTalk captures management API calls issued to all NFV services, and produces more interpretable results by significantly reducing the size of the provenance graphs (about 3.6 times reduction via the multi-level pruning scheme and two times reduction via the aggregation scheme). Our user studies show that ProvTalk facilitates the analysis task of real-world users by generating more interpretable results.
DOI: 10.14722/ndss.2018.23141
发表时间: 2018
期刊: --
影响因子: --
作者:
Wajih Ul Hassan;Mark Lemay;Nuraini Aguse;Adam Bates;Thomas Moyer
通讯作者: Wajih Ul Hassan;Mark Lemay;Nuraini Aguse;Adam Bates;Thomas Moyer
DOI: --
发表时间: 2018
期刊: --
影响因子: --
作者:
Qi Wang;Wajih Ul Hassan;Adam Bates;Carl A. Gunter
通讯作者: Qi Wang;Wajih Ul Hassan;Adam Bates;Carl A. Gunter
DOI: 10.1145/3243734.3243776
发表时间: 2018-01
期刊: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
Thomas Pasquier;Xueyuan Han;Thomas Moyer;Adam Bates;O. Hermant;D. Eyers;J. Bacon;M. Seltzer
通讯作者: Thomas Pasquier;Xueyuan Han;Thomas Moyer;Adam Bates;O. Hermant;D. Eyers;J. Bacon;M. Seltzer
DOI: 10.1145/3243734.3243749
发表时间: 2018-10
期刊: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
Haopei Wang;Guangliang Yang;Phakpoom Chinprutthiwong;Lei Xu;Yangyong Zhang;G. Gu
通讯作者: Haopei Wang;Guangliang Yang;Phakpoom Chinprutthiwong;Lei Xu;Yangyong Zhang;G. Gu