EvIDencE: Testing Intrusion Detection Systems in Virtualized Environments

证据:在虚拟化环境中测试入侵检测系统

基本信息

项目摘要

In recent years, virtualization has received increasing interest, both from industry and academia, as a way to reduce costs through server consolidation and to enhance the flexibility of physical infrastructures. While virtualization provides many benefits, it also introduces new challenges, such as the potential threats and vulnerabilities that come with the introduction of Virtual Machine Monitors (VMMs) and the allocation of potentially multiple Virtual Machines (VMs) on the same physical server. Security has often been named as one of the major concerns for users of modern virtualized service infrastructures, given that with the introduction of a virtualization layer, a new target - the virtualization platform - is introduced that may be exploited by attackers. Intrusion detection systems (IDSes) are a common defensive instrument against security threats and the increasing adoption of virtualization has lead to the emergence of a novel class of IDSes specifically designed to operate in virtualized environments.However, no methods and techniques have been proposed so far for testing in a realistic and reliable manner how well a given IDS for a virtualized environment performs. To minimize the risk of security breaches, such methods and techniques are crucially important. The proposed project EvIDencE provides a detailed research agenda to address this issue by developing an approach for generating virtualization-specific malicious workloads, as well as metrics and measurement methodologies, enabling the testing of modern IDSes in a rigorous and representative manner. To achieve these goals, novel methods are needed for generating malicious workloads containing attacks targeted at VMMs and exploiting virtualization-specific vulnerabilities that are representative of modern virtualization platforms. Furthermore, novel metrics for quantifying the attack detection accuracy are needed that explicitly take into account the dynamic resource provisioning behavior of modern VMMs, which can normally significantly influence the behavior of the IDS under test. The proposed project will enable the representative testing of IDSes in virtualized environments by contributing: i) a framework for executing representative malicious workloads based on hypercall attacks, ii) a set of novel IDS testing metrics, and iii) a scientifically rigorous IDS testing methodology. The developed techniques can be used by researchers to test novel IDS algorithms and architectures with respect to specific IDS properties that are subject of research. Further, they can be used by industrial software architects and IT security officers to compare different IDSes in terms of their attack detection accuracy in order to deploy an IDS that operates optimally in a given environment. Finally, the techniques can be used to tune and optimize the configuration of an already deployed IDS, thus reducing the risks of a security breach.
近年来,虚拟化作为通过服务器整合降低成本和增强物理基础设施灵活性的一种方式,越来越受到业界和学术界的关注。虽然虚拟化提供了许多好处,但它也带来了新的挑战,例如引入虚拟机监视器 (VMM) 以及在同一物理服务器上分配潜在的多个虚拟机 (VM) 所带来的潜在威胁和漏洞。安全性常常被认为是现代虚拟化服务基础设施用户最关心的问题之一,因为随着虚拟化层的引入,引入了一个可能被攻击者利用的新目标——虚拟化平台。入侵检测系统 (IDS) 是针对安全威胁的常见防御工具,虚拟化的日益普及导致了专门设计用于在虚拟化环境中运行的一类新型 IDS 的出现。但是,到目前为止,还没有提出任何方法和技术来以现实且可靠的方式测试给定 IDS 在虚拟化环境中的性能。为了最大限度地降低安全漏洞的风险,这些方法和技术至关重要。拟议的项目 EvIDencE 提供了详细的研究议程,通过开发一种生成虚拟化特定恶意工作负载的方法以及指标和测量方法来解决这个问题,从而能够以严格且具有代表性的方式测试现代 IDS。为了实现这些目标,需要新的方法来生成包含针对 VMM 的攻击的恶意工作负载,并利用代表现代虚拟化平台的虚拟化特定漏洞。此外,需要用于量化攻击检测准确性的新指标,明确考虑现代 VMM 的动态资源配置行为,这通常会显着影响被测 IDS 的行为。拟议的项目将通过贡献以下内容,在虚拟化环境中实现 IDS 的代表性测试:i)用于执行基于超级调用攻击的代表性恶意工作负载的框架,ii)一组新颖的 IDS 测试指标,以及 iii)科学严谨的 IDS 测试方法。研究人员可以使用所开发的技术来测试新颖的 IDS 算法和架构,以了解作为研究主题的特定 IDS 属性。此外,工业软件架构师和 IT 安全人员还可以使用它们来比较不同 IDS 的攻击检测准确性,以便部署在给定环境中以最佳方式运行的 IDS。最后,这些技术可用于调整和优化已部署的 IDS 的配置,从而降低安全漏洞的风险。

项目成果

期刊论文数量(7)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Benchmarking Intrusion Detection Systems with Adaptive Provisioning of Virtualized Resources
通过虚拟化资源的自适应配置对入侵检测系统进行基准测试
  • DOI:
    10.1007/978-3-319-47474-8_22
  • 发表时间:
    2017
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Aleksandar Milenkoski;K. R. Jayaram;Samuel Kounev
  • 通讯作者:
    Samuel Kounev
The Vision of Self-aware Reordering of Security Network Function Chains
安全网络功能链自我意识重新排序的愿景
CUP: A Formalism for Expressing Cloud Usage Patterns for Experts and Non-Experts
CUP:为专家和非专家表达云使用模式的形式主义
  • DOI:
    10.1109/mcc.2018.032591618
  • 发表时间:
    2018
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Aleksandar Milenkoski;Alexandru Iosup;Samuel Kounev;Kai Sachs;Diane E. Mularz;Jonathan A. Curtiss;Jason J. Ding;Florian Rosenberg;Piotr Rygielski
  • 通讯作者:
    Piotr Rygielski
Software Architectures for Self-protection in IaaS Clouds
IaaS 云中自我保护的软件架构
  • DOI:
    10.1007/978-3-319-47474-8_21
  • 发表时间:
    2017
  • 期刊:
  • 影响因子:
    0
  • 作者:
    K. R. Jayaram;Aleksandar Milenkoski;Samuel Kounev
  • 通讯作者:
    Samuel Kounev
Performance Influence of Security Function Chain Ordering
安全功能链排序对性能的影响
{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Professor Dr.-Ing. Samuel Kounev其他文献

Professor Dr.-Ing. Samuel Kounev的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Professor Dr.-Ing. Samuel Kounev', 18)}}的其他基金

MODELS: performance MODELing of Software-defined data center networks
模型:软件定义数据中心网络的性能建模
  • 批准号:
    317105593
  • 财政年份:
    2016
  • 资助金额:
    --
  • 项目类别:
    Research Grants
PRISMA: Efficient Algorithms and Methods for Online Extraction of Performance Models in Virtualized Environments
PRISMA:虚拟化环境中在线提取性能模型的高效算法和方法
  • 批准号:
    251959028
  • 财政年份:
    2015
  • 资助金额:
    --
  • 项目类别:
    Research Grants
Autonomes Performanz- und Ressourcen-Management in dynamischen, dienstorientierten Umgebungen
动态、面向服务的环境中的自主性能和资源管理
  • 批准号:
    113520543
  • 财政年份:
    2009
  • 资助金额:
    --
  • 项目类别:
    Independent Junior Research Groups
Modellierung und Bewertung von Event-basierten Systemen
基于事件的系统的建模和评估
  • 批准号:
    20128456
  • 财政年份:
    2005
  • 资助金额:
    --
  • 项目类别:
    Research Fellowships

相似海外基金

Digital Solutions For Accelerated Battery Testing
加速电池测试的数字解决方案
  • 批准号:
    10107050
  • 财政年份:
    2024
  • 资助金额:
    --
  • 项目类别:
    EU-Funded
Enabling Reliable Testing Of SMLM Datasets
实现 SMLM 数据集的可靠测试
  • 批准号:
    BB/X01858X/1
  • 财政年份:
    2024
  • 资助金额:
    --
  • 项目类别:
    Research Grant
Collaborative Research: BoCP-Implementation: Testing Evolutionary Models of Biotic Survival and Recovery from the Permo-Triassic Mass Extinction and Climate Crisis
合作研究:BoCP-实施:测试二叠纪-三叠纪大规模灭绝和气候危机中生物生存和恢复的进化模型
  • 批准号:
    2325380
  • 财政年份:
    2024
  • 资助金额:
    --
  • 项目类别:
    Standard Grant
STTR Phase II: Fabrication and Structural Testing of a 3D Concrete Printed Anchor for Floating Offshore Wind
STTR 第二阶段:用于浮动海上风电的 3D 混凝土打印锚的制造和结构测试
  • 批准号:
    2333306
  • 财政年份:
    2024
  • 资助金额:
    --
  • 项目类别:
    Cooperative Agreement
Collaborative Research: Superinvaders: testing a general hypothesis of forest invasions by woody species across the Americas
合作研究:超级入侵者:测试美洲木本物种入侵森林的一般假设
  • 批准号:
    2331278
  • 财政年份:
    2024
  • 资助金额:
    --
  • 项目类别:
    Standard Grant
Testing Theorems in Analytic Function Theory, Harmonic Analysis and Operator Theory
解析函数论、调和分析和算子理论中的检验定理
  • 批准号:
    2349868
  • 财政年份:
    2024
  • 资助金额:
    --
  • 项目类别:
    Standard Grant
Developing and Testing Innovations: Computer Science Through Engineering Design in New York
开发和测试创新:纽约的工程设计中的计算机科学
  • 批准号:
    2341962
  • 财政年份:
    2024
  • 资助金额:
    --
  • 项目类别:
    Standard Grant
Sustaining Innovative Tools to Expand Youth-Friendly HIV Self-Testing (S-ITEST)
维持创新工具以扩大青少年友好型艾滋病毒自我检测 (S-ITEST)
  • 批准号:
    10933892
  • 财政年份:
    2024
  • 资助金额:
    --
  • 项目类别:
Testing the genetic impact on the internal and external shape of teeth in non-human primates
测试遗传对非人类灵长类动物牙齿内部和外部形状的影响
  • 批准号:
    2341544
  • 财政年份:
    2024
  • 资助金额:
    --
  • 项目类别:
    Standard Grant
CAREER: Informed Testing — From Full-Field Characterization of Mechanically Graded Soft Materials to Student Equity in the Classroom
职业:知情测试 – 从机械分级软材料的全场表征到课堂上的学生公平
  • 批准号:
    2338371
  • 财政年份:
    2024
  • 资助金额:
    --
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了