EvIDencE: Testing Intrusion Detection Systems in Virtualized Environments
EvIDencE: Testing Intrusion Detection Systems in Virtualized Environments
批准号:
289129390
负责人:
Professor Dr.-Ing. Samuel Kounev
金额:
$0.0万
依托单位国家:
德国
项目类别:
Research Grants
财政年份:
2016
资助国家:
德国
项目状态:
已结题
起止时间:
2015-12-31 至 2019-12-31
中文摘要
近年来,虚拟化作为通过服务器整合降低成本和增强物理基础设施灵活性的一种方式,受到了工业界和学术界越来越多的关注。虽然虚拟化提供了许多好处,但它也带来了新的挑战,例如引入虚拟机集群(VMM)以及在同一物理服务器上分配多个虚拟机(VM)所带来的潜在威胁和漏洞。安全性通常被认为是现代虚拟化服务基础设施的用户的主要关注点之一,因为随着虚拟化层的引入,引入了可能被攻击者利用的新目标-虚拟化平台。入侵检测系统(IDS)是一种常见的防御安全威胁的工具,随着虚拟化技术的不断发展,出现了一类专门设计用于虚拟化环境的IDS,但是目前还没有一种方法和技术能够真实可靠地测试虚拟化环境下IDS的性能。为了最大限度地降低安全漏洞的风险,这些方法和技术至关重要。拟议的项目EvIDencE提供了一个详细的研究议程,通过开发一种生成特定于虚拟化的恶意工作负载的方法以及指标和测量方法来解决这个问题,从而能够以严格和有代表性的方式测试现代IDS。为了实现这些目标,需要新的方法来生成包含针对VMM的攻击的恶意工作负载,并利用代表现代虚拟化平台的虚拟化特定漏洞。此外,需要明确考虑现代VMM的动态资源配置行为的新的度量来量化攻击检测准确性,这通常会显著影响测试中的IDS的行为。拟议的项目将通过贡献:i)基于hypercall攻击执行代表性恶意工作负载的框架,ii)一组新的IDS测试指标,以及iii)科学严谨的IDS测试方法,在虚拟化环境中实现IDS的代表性测试。所开发的技术可以被研究人员用来测试新的IDS算法和体系结构相对于特定的IDS属性的研究对象。此外,工业软件架构师和IT安全官员可以使用它们来比较不同IDS的攻击检测准确性,以便部署在给定环境中最佳运行的IDS。最后,这些技术可以用于调整和优化已经部署的IDS的配置,从而降低安全漏洞的风险。
英文摘要
In recent years, virtualization has received increasing interest, both from industry and academia, as a way to reduce costs through server consolidation and to enhance the flexibility of physical infrastructures. While virtualization provides many benefits, it also introduces new challenges, such as the potential threats and vulnerabilities that come with the introduction of Virtual Machine Monitors (VMMs) and the allocation of potentially multiple Virtual Machines (VMs) on the same physical server. Security has often been named as one of the major concerns for users of modern virtualized service infrastructures, given that with the introduction of a virtualization layer, a new target - the virtualization platform - is introduced that may be exploited by attackers. Intrusion detection systems (IDSes) are a common defensive instrument against security threats and the increasing adoption of virtualization has lead to the emergence of a novel class of IDSes specifically designed to operate in virtualized environments.However, no methods and techniques have been proposed so far for testing in a realistic and reliable manner how well a given IDS for a virtualized environment performs. To minimize the risk of security breaches, such methods and techniques are crucially important. The proposed project EvIDencE provides a detailed research agenda to address this issue by developing an approach for generating virtualization-specific malicious workloads, as well as metrics and measurement methodologies, enabling the testing of modern IDSes in a rigorous and representative manner. To achieve these goals, novel methods are needed for generating malicious workloads containing attacks targeted at VMMs and exploiting virtualization-specific vulnerabilities that are representative of modern virtualization platforms. Furthermore, novel metrics for quantifying the attack detection accuracy are needed that explicitly take into account the dynamic resource provisioning behavior of modern VMMs, which can normally significantly influence the behavior of the IDS under test. The proposed project will enable the representative testing of IDSes in virtualized environments by contributing: i) a framework for executing representative malicious workloads based on hypercall attacks, ii) a set of novel IDS testing metrics, and iii) a scientifically rigorous IDS testing methodology. The developed techniques can be used by researchers to test novel IDS algorithms and architectures with respect to specific IDS properties that are subject of research. Further, they can be used by industrial software architects and IT security officers to compare different IDSes in terms of their attack detection accuracy in order to deploy an IDS that operates optimally in a given environment. Finally, the techniques can be used to tune and optimize the configuration of an already deployed IDS, thus reducing the risks of a security breach.
期刊论文(7)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
Benchmarking Intrusion Detection Systems with Adaptive Provisioning of Virtualized Resources
通过虚拟化资源的自适应配置对入侵检测系统进行基准测试
DOI:
10.1007/978-3-319-47474-8_22
发表时间:
2017
期刊:
影响因子:
--
作者:
[Aleksandar Milenkoski, K. R. Jayaram, Samuel Kounev]
通讯作者:
Samuel Kounev
The Vision of Self-aware Reordering of Security Network Function Chains
安全网络功能链自我意识重新排序的愿景
DOI:
10.1145/3185768.3186309
发表时间:
2018
期刊:
Companion of the 2018 ACM/SPEC International Conference on Performance Engineering
影响因子:
--
作者:
[Lukas Iffländer, Jürgen Walter, Simon Eismann, Samuel Kounev]
通讯作者:
Samuel Kounev
CUP: A Formalism for Expressing Cloud Usage Patterns for Experts and Non-Experts
CUP:为专家和非专家表达云使用模式的形式主义
DOI:
10.1109/mcc.2018.032591618
发表时间:
2018
期刊:
IEEE Cloud Computing
影响因子:
--
作者:
[Aleksandar Milenkoski, Alexandru Iosup, Samuel Kounev, Kai Sachs, Diane E. Mularz, Jonathan A. Curtiss, Jason J. Ding, Florian Rosenberg, Piotr Rygielski]
通讯作者:
Piotr Rygielski
Software Architectures for Self-protection in IaaS Clouds
IaaS 云中自我保护的软件架构
DOI:
10.1007/978-3-319-47474-8_21
发表时间:
2017
期刊:
影响因子:
--
作者:
[K. R. Jayaram, Aleksandar Milenkoski, Samuel Kounev]
通讯作者:
Samuel Kounev
DOI:
10.1145/3302541.3311965
发表时间:
2019
期刊:
Companion of the 2019 ACM/SPEC International Conference on Performance Engineering
影响因子:
--
作者:
[Lukas Iffländer, Nicolas Fella]
通讯作者:
Nicolas Fella
共 7 条
MODELS: performance MODELing of Software-defined data center networks
-
批准号:317105593
-
项目类别:Research Grants
-
资助金额:$0.0万
-
财政年份:2016
-
负责人:Professor Dr.-Ing. Samuel Kounev
-
依托单位:
PRISMA: Efficient Algorithms and Methods for Online Extraction of Performance Models in Virtualized Environments
-
批准号:251959028
-
项目类别:Research Grants
-
资助金额:$0.0万
-
财政年份:2015
-
负责人:Professor Dr.-Ing. Samuel Kounev
-
依托单位:
Autonomes Performanz- und Ressourcen-Management in dynamischen, dienstorientierten Umgebungen
-
批准号:113520543
-
项目类别:Independent Junior Research Groups
-
资助金额:$0.0万
-
财政年份:2009
-
负责人:Professor Dr.-Ing. Samuel Kounev
-
依托单位:
Modellierung und Bewertung von Event-basierten Systemen
-
批准号:20128456
-
项目类别:Research Fellowships
-
资助金额:$0.0万
-
财政年份:2005
-
负责人:Professor Dr.-Ing. Samuel Kounev
-
依托单位:
海外基金