A novel covert channel detection method in cloud based on XSRM and improved event association algorithm

被引:4
|
作者
Wang, Lina [1 ,2 ]
Liu, Weijie [1 ,3 ]
Kumar, Neeraj [4 ]
He, Debiao [1 ,2 ]
Tan, Cheng [1 ]
Gao, Debin [3 ]
机构
[1] Wuhan Univ, Comp Sch, Wuhan, Peoples R China
[2] Minist Educ, Key Lab Aerosp Informat Secur & Trusted Comp, Wuhan, Peoples R China
[3] Singapore Management Univ, Sch Informat Syst, Singapore, Singapore
[4] Thapar Univ, Dept Comp Sci & Engn, Patiala, Punjab, India
基金
中国国家自然科学基金;
关键词
cloud security; covert channel detection; shared resource matrix; event association analysis; SECURITY; STORAGE;
D O I
10.1002/sec.1560
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Covert channel is a major threat to the information system security and commonly found in operating systems, especially in cloud computing environment. Owing to the characteristics in cloud computing environment such as resources sharing and logic boundaries, covert channels become more varied and difficult to find. Focusing on those problems, this paper presents a universal method for detecting covert channel automatically. To achieve a global detection, we leveraged a virtual machine event record mechanism in hypervisor to gather necessary metadata. Combining the shared resources matrix methodology with events association mechanism, we proposed a distinctive algorithm that can accurately locate and analyze malicious covert channels from the respect of behaviors. Compared with the popular statistical test methods focusing on the single covert channel, our method is capable of recognizing and detecting more covert channels in real time. Experimental results show that this method is not only able to detect multilevel and multiform covert channels in cloud environment effectively but also facilitates the implementation and deployment in practical scenarios without modifying the existing system. Copyright (C) 2016 John Wiley & Sons, Ltd.
引用
收藏
页码:3543 / 3557
页数:15
相关论文
共 50 条
  • [11] Study of covert channel algorithm based on packet order
    Li Lan
    Lei Jie
    ADVANCED COMPUTER TECHNOLOGY, NEW EDUCATION, PROCEEDINGS, 2007, : 268 - 269
  • [12] A Novel Denoising Algorithm of Electromagnetic Ultrasonic Detection Signal Based on Improved EEMD Method
    Gong, Wenkang
    Liu, Qi
    Du, Wenhao
    Xu, Weichen
    Wang, Gang
    JOURNAL OF ELECTRICAL AND COMPUTER ENGINEERING, 2018, 2018
  • [13] Highway Event Detection Algorithm Based on Improved Fast Peak Clustering
    Pei, Lili
    Sun, Zhaoyun
    Han, Yuxi
    Li, Wei
    Zhao, Huaixin
    MATHEMATICAL PROBLEMS IN ENGINEERING, 2021, 2021
  • [14] Event-based improved FAST corner feature detection algorithm
    Wen, Shiguang
    An, Wen
    Li, Haojia
    Wei, Hongyan
    PROCEEDINGS OF THE 2019 31ST CHINESE CONTROL AND DECISION CONFERENCE (CCDC 2019), 2019, : 4956 - 4961
  • [15] Lidar cloud detection based on improved simple multiscale method
    Chen S.
    Wang J.
    Chen H.
    Zhang Y.
    Guo P.
    Nian X.
    Sun Z.
    Chen S.
    Hongwai yu Jiguang Gongcheng/Infrared and Laser Engineering, 2020, 49
  • [16] Whispers in the cloud storage: A novel cross-user deduplication-based covert channel design
    Hermine Hovhannisyan
    Wen Qi
    Kejie Lu
    Rongwei Yang
    Jianping Wang
    Peer-to-Peer Networking and Applications, 2018, 11 : 277 - 286
  • [17] Covert timing channel detection method based on time interval and payload length analysis
    Han, Jiaxuan
    Huang, Cheng
    Shi, Fan
    Liu, Jiayong
    COMPUTERS & SECURITY, 2020, 97
  • [18] Whispers in the cloud storage: A novel cross-user deduplication-based covert channel design
    Hovhannisyan, Hermine
    Qi, Wen
    Lu, Kejie
    Yang, Rongwei
    Wang, Jianping
    PEER-TO-PEER NETWORKING AND APPLICATIONS, 2018, 11 (02) : 277 - 286
  • [19] A Novel Dynamic Task Scheduling Algorithm Based on Improved Genetic Algorithm in Cloud Computing
    Ma, Juntao
    Li, Weitao
    Fu, Tian
    Yan, Lili
    Hu, Guojie
    WIRELESS COMMUNICATIONS, NETWORKING AND APPLICATIONS, WCNA 2014, 2016, 348 : 829 - 835
  • [20] Intrusion detection method based on an improved Bayesian algorithm
    Wen, Qiao
    Wang, Weiping
    Jisuanji Gongcheng/Computer Engineering, 2006, 32 (12): : 160 - 162