ProvTalk: Towards Interpretable Multi-level Provenance Analysis in Networking Functions Virtualization (NFV)
ProvTalk: Towards Interpretable Multi-level Provenance Analysis in Networking Functions Virtualization (NFV)
复制标题
ProvTalk:网络功能虚拟化 (NFV) 中的可解释多级来源分析
DOI:
10.14722/ndss.2022.23103
复制
发表时间:
2022
期刊:
影响因子:
--
通讯作者:
Lingyu Wang
中科院分区:
文献类型:
--
作者:
Azadeh Tabiban;Heyang Zhao;Yosr Jarraya;M. Pourzandi;Mengyuan Zhang;Lingyu Wang
—Network functions virtualization (NFV) enables agile deployment of network services on top of clouds. However, as NFV involves multiple levels of abstraction representing the same components, pinpointing the root cause of security incidents can become challenging. For instance, a security incident may be detected at a different level from where its root cause operations were conducted with no obvious link between the two. Moreover, existing provenance analysis techniques may produce results that are impractically large for human analysts to interpret due to the inherent complexity of NFV. In this paper, we propose ProvTalk, a provenance analysis system that handles the unique multi-level nature of NFV and assists the analyst to identify the root cause of security incidents. Specifically, we first define a multi-level provenance model to capture the dependencies between NFV levels. Next, we improve the interpretability through three novel techniques, i.e., multi-level pruning, mining-based aggregation, and rule-based natural language translation. We implement ProvTalk on a Tacker-OpenStack NFV platform and validate its effectiveness based on real-world security incidents. We demonstrate that ProvTalk captures management API calls issued to all NFV services, and produces more interpretable results by significantly reducing the size of the provenance graphs (about 3.6 times reduction via the multi-level pruning scheme and two times reduction via the aggregation scheme). Our user studies show that ProvTalk facilitates the analysis task of real-world users by generating more interpretable results.
登录
查看更多内容
DOI:
10.14722/ndss.2018.23141
发表时间:
2018
期刊:
--
影响因子:
--
作者:
Wajih Ul Hassan;Mark Lemay;Nuraini Aguse;Adam Bates;Thomas Moyer
通讯作者:
Wajih Ul Hassan;Mark Lemay;Nuraini Aguse;Adam Bates;Thomas Moyer
DOI:
--
发表时间:
2018
期刊:
--
影响因子:
--
作者:
Qi Wang;Wajih Ul Hassan;Adam Bates;Carl A. Gunter
通讯作者:
Qi Wang;Wajih Ul Hassan;Adam Bates;Carl A. Gunter
DOI:
10.1145/3243734.3243776
发表时间:
2018-01
期刊:
Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
Thomas Pasquier;Xueyuan Han;Thomas Moyer;Adam Bates;O. Hermant;D. Eyers;J. Bacon;M. Seltzer
通讯作者:
Thomas Pasquier;Xueyuan Han;Thomas Moyer;Adam Bates;O. Hermant;D. Eyers;J. Bacon;M. Seltzer
DOI:
10.1145/3243734.3243749
发表时间:
2018-10
期刊:
Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
Haopei Wang;Guangliang Yang;Phakpoom Chinprutthiwong;Lei Xu;Yangyong Zhang;G. Gu
通讯作者:
Haopei Wang;Guangliang Yang;Phakpoom Chinprutthiwong;Lei Xu;Yangyong Zhang;G. Gu