An Anomaly Detection Fabric for Clouds Based on Collaborative VM Communities
An Anomaly Detection Fabric for Clouds Based on Collaborative VM Communities
复制标题
基于协作虚拟机社区的云异常检测结构
DOI:
--
复制
发表时间:
2017
期刊:
影响因子:
--
通讯作者:
Fareed Zaffar
中科院分区:
文献类型:
--
作者:
Rashid Tahir;M. Caesar;Ali Raza;Mazhar Naqvi;Fareed Zaffar
The vast attack surface of clouds presents a challenge in deploying scalable and effective defenses. Traditional security mechanisms, which work from inside the VM fail to provide strong protection as attackers can bypass them easily. The only available option is to provide security from the layer below the VM i.e., the hypervisor. Previous works that attempt to secure VMs from "outside" either incur substantial space or compute overheads making them slow and impractical or require modifications to the OS or the application codebase. To address these issues, we propose an anomaly detection fabric for clouds based on system call monitoring, which compresses the stream of system calls at their source making the system scalable and near real-time. Our system requires no modifications to the guest OS or the application making it ideal for the data center setting. Additionally, for robust and early detection of threats, we leverage the notion of VM/container communities that share information about attacks in their early stages to provide immunity to the entire deployment. We make certain aspects of the system flexible so that vendors can tune metrics to offer customized protection to clients based on their workload types. Detailed evaluation on a prototype implementation on KVM substantiates our claims.