EvIDencE: Testing Intrusion Detection Systems in Virtualized Environments
EvIDencE: Testing Intrusion Detection Systems in Virtualized Environments
批准号:
289129390
负责人:
Professor Dr.-Ing. Samuel Kounev
金额:
$0.0万
依托单位国家:
德国
项目类别:
Research Grants
财政年份:
2016
资助国家:
德国
项目状态:
已结题
起止时间:
2015-12-31 至 2019-12-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
In recent years, virtualization has received increasing interest, both from industry and academia, as a way to reduce costs through server consolidation and to enhance the flexibility of physical infrastructures. While virtualization provides many benefits, it also introduces new challenges, such as the potential threats and vulnerabilities that come with the introduction of Virtual Machine Monitors (VMMs) and the allocation of potentially multiple Virtual Machines (VMs) on the same physical server. Security has often been named as one of the major concerns for users of modern virtualized service infrastructures, given that with the introduction of a virtualization layer, a new target - the virtualization platform - is introduced that may be exploited by attackers. Intrusion detection systems (IDSes) are a common defensive instrument against security threats and the increasing adoption of virtualization has lead to the emergence of a novel class of IDSes specifically designed to operate in virtualized environments.However, no methods and techniques have been proposed so far for testing in a realistic and reliable manner how well a given IDS for a virtualized environment performs. To minimize the risk of security breaches, such methods and techniques are crucially important. The proposed project EvIDencE provides a detailed research agenda to address this issue by developing an approach for generating virtualization-specific malicious workloads, as well as metrics and measurement methodologies, enabling the testing of modern IDSes in a rigorous and representative manner. To achieve these goals, novel methods are needed for generating malicious workloads containing attacks targeted at VMMs and exploiting virtualization-specific vulnerabilities that are representative of modern virtualization platforms. Furthermore, novel metrics for quantifying the attack detection accuracy are needed that explicitly take into account the dynamic resource provisioning behavior of modern VMMs, which can normally significantly influence the behavior of the IDS under test. The proposed project will enable the representative testing of IDSes in virtualized environments by contributing: i) a framework for executing representative malicious workloads based on hypercall attacks, ii) a set of novel IDS testing metrics, and iii) a scientifically rigorous IDS testing methodology. The developed techniques can be used by researchers to test novel IDS algorithms and architectures with respect to specific IDS properties that are subject of research. Further, they can be used by industrial software architects and IT security officers to compare different IDSes in terms of their attack detection accuracy in order to deploy an IDS that operates optimally in a given environment. Finally, the techniques can be used to tune and optimize the configuration of an already deployed IDS, thus reducing the risks of a security breach.
期刊论文(7)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
Benchmarking Intrusion Detection Systems with Adaptive Provisioning of Virtualized Resources
通过虚拟化资源的自适应配置对入侵检测系统进行基准测试
DOI:
10.1007/978-3-319-47474-8_22
发表时间:
2017
期刊:
影响因子:
--
作者:
[Aleksandar Milenkoski, K. R. Jayaram, Samuel Kounev]
通讯作者:
Samuel Kounev
The Vision of Self-aware Reordering of Security Network Function Chains
安全网络功能链自我意识重新排序的愿景
DOI:
10.1145/3185768.3186309
发表时间:
2018
期刊:
Companion of the 2018 ACM/SPEC International Conference on Performance Engineering
影响因子:
--
作者:
[Lukas Iffländer, Jürgen Walter, Simon Eismann, Samuel Kounev]
通讯作者:
Samuel Kounev
CUP: A Formalism for Expressing Cloud Usage Patterns for Experts and Non-Experts
CUP:为专家和非专家表达云使用模式的形式主义
DOI:
10.1109/mcc.2018.032591618
发表时间:
2018
期刊:
IEEE Cloud Computing
影响因子:
--
作者:
[Aleksandar Milenkoski, Alexandru Iosup, Samuel Kounev, Kai Sachs, Diane E. Mularz, Jonathan A. Curtiss, Jason J. Ding, Florian Rosenberg, Piotr Rygielski]
通讯作者:
Piotr Rygielski
Software Architectures for Self-protection in IaaS Clouds
IaaS 云中自我保护的软件架构
DOI:
10.1007/978-3-319-47474-8_21
发表时间:
2017
期刊:
影响因子:
--
作者:
[K. R. Jayaram, Aleksandar Milenkoski, Samuel Kounev]
通讯作者:
Samuel Kounev
DOI:
10.1145/3302541.3311965
发表时间:
2019
期刊:
Companion of the 2019 ACM/SPEC International Conference on Performance Engineering
影响因子:
--
作者:
[Lukas Iffländer, Nicolas Fella]
通讯作者:
Nicolas Fella
共 7 条
MODELS: performance MODELing of Software-defined data center networks
-
批准号:317105593
-
项目类别:Research Grants
-
资助金额:$0.0万
-
财政年份:2016
-
负责人:Professor Dr.-Ing. Samuel Kounev
-
依托单位:
PRISMA: Efficient Algorithms and Methods for Online Extraction of Performance Models in Virtualized Environments
-
批准号:251959028
-
项目类别:Research Grants
-
资助金额:$0.0万
-
财政年份:2015
-
负责人:Professor Dr.-Ing. Samuel Kounev
-
依托单位:
Autonomes Performanz- und Ressourcen-Management in dynamischen, dienstorientierten Umgebungen
-
批准号:113520543
-
项目类别:Independent Junior Research Groups
-
资助金额:$0.0万
-
财政年份:2009
-
负责人:Professor Dr.-Ing. Samuel Kounev
-
依托单位:
Modellierung und Bewertung von Event-basierten Systemen
-
批准号:20128456
-
项目类别:Research Fellowships
-
资助金额:$0.0万
-
财政年份:2005
-
负责人:Professor Dr.-Ing. Samuel Kounev
-
依托单位:
海外基金