An Anomaly Detection Fabric for Clouds Based on Collaborative VM Communities

An Anomaly Detection Fabric for Clouds Based on Collaborative VM Communities
复制标题

基于协作虚拟机社区的云异常检测结构

DOI:
--
复制
发表时间:
2017
期刊:
IEEE/ACM International Symposium on Cluster, Cloud and Internet Computing
影响因子:
--
通讯作者:
Fareed Zaffar
Fareed Zaffar
中科院分区:
--
文献类型:
--
作者:
Rashid Tahir;M. Caesar;Ali Raza;Mazhar Naqvi;Fareed Zaffar

文献摘要

被引文献

相似文献

云的巨大攻击面对部署可扩展和有效的防御提出了挑战。在VM内部工作的传统安全机制无法提供强大的保护,因为攻击者可以很容易地绕过它们。唯一可用的选项是从VM下面的层(即管理程序)提供安全性。以前试图从“外部”保护vm的工作要么会产生大量的空间,要么会导致计算开销,使它们变得缓慢和不切实际,要么需要修改操作系统或应用程序代码库。为了解决这些问题,我们提出了一种基于系统调用监控的云异常检测结构,它在源处压缩系统调用流,使系统具有可扩展性和接近实时性。我们的系统不需要修改客户操作系统或应用程序,使其成为数据中心设置的理想选择。此外,为了及早检测威胁,我们利用VM/容器社区的概念,在早期阶段共享有关攻击的信息,以提供对整个部署的免疫力。我们使系统的某些方面变得灵活,以便供应商可以调整指标,根据客户的工作负载类型为他们提供定制的保护。对KVM原型实现的详细评估证实了我们的说法。
The vast attack surface of clouds presents a challenge in deploying scalable and effective defenses. Traditional security mechanisms, which work from inside the VM fail to provide strong protection as attackers can bypass them easily. The only available option is to provide security from the layer below the VM i.e., the hypervisor. Previous works that attempt to secure VMs from "outside" either incur substantial space or compute overheads making them slow and impractical or require modifications to the OS or the application codebase. To address these issues, we propose an anomaly detection fabric for clouds based on system call monitoring, which compresses the stream of system calls at their source making the system scalable and near real-time. Our system requires no modifications to the guest OS or the application making it ideal for the data center setting. Additionally, for robust and early detection of threats, we leverage the notion of VM/container communities that share information about attacks in their early stages to provide immunity to the entire deployment. We make certain aspects of the system flexible so that vendors can tune metrics to offer customized protection to clients based on their workload types. Detailed evaluation on a prototype implementation on KVM substantiates our claims.