A novel covert channel detection method in cloud based on XSRM and improved event association algorithm

被引:4
|
作者
Wang, Lina [1 ,2 ]
Liu, Weijie [1 ,3 ]
Kumar, Neeraj [4 ]
He, Debiao [1 ,2 ]
Tan, Cheng [1 ]
Gao, Debin [3 ]
机构
[1] Wuhan Univ, Comp Sch, Wuhan, Peoples R China
[2] Minist Educ, Key Lab Aerosp Informat Secur & Trusted Comp, Wuhan, Peoples R China
[3] Singapore Management Univ, Sch Informat Syst, Singapore, Singapore
[4] Thapar Univ, Dept Comp Sci & Engn, Patiala, Punjab, India
基金
中国国家自然科学基金;
关键词
cloud security; covert channel detection; shared resource matrix; event association analysis; SECURITY; STORAGE;
D O I
10.1002/sec.1560
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Covert channel is a major threat to the information system security and commonly found in operating systems, especially in cloud computing environment. Owing to the characteristics in cloud computing environment such as resources sharing and logic boundaries, covert channels become more varied and difficult to find. Focusing on those problems, this paper presents a universal method for detecting covert channel automatically. To achieve a global detection, we leveraged a virtual machine event record mechanism in hypervisor to gather necessary metadata. Combining the shared resources matrix methodology with events association mechanism, we proposed a distinctive algorithm that can accurately locate and analyze malicious covert channels from the respect of behaviors. Compared with the popular statistical test methods focusing on the single covert channel, our method is capable of recognizing and detecting more covert channels in real time. Experimental results show that this method is not only able to detect multilevel and multiform covert channels in cloud environment effectively but also facilitates the implementation and deployment in practical scenarios without modifying the existing system. Copyright (C) 2016 John Wiley & Sons, Ltd.
引用
收藏
页码:3543 / 3557
页数:15
相关论文
共 50 条
  • [41] A novel covert communication method based on WCDMA
    Wu, H. Y.
    Hu, A. Q.
    INDUSTRIAL INSTRUMENTATION AND CONTROL SYSTEMS II, PTS 1-3, 2013, 336-338 : 1611 - 1615
  • [42] An improved algorithm for order detection of multipath channel
    Li, Yu
    Gu, Yujie
    Chen, Kangsheng
    TENCON 2006 - 2006 IEEE REGION 10 CONFERENCE, VOLS 1-4, 2006, : 1071 - +
  • [43] A Novel Covert Timing Channel Detection Approach for Online Network Traffic
    Rezaei, Fahimeh
    Hempel, Michael
    Shrestha, Pradhumna Lal
    Rakshit, Sushanta Mohan
    Sharif, Hamid
    2015 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2015, : 737 - 738
  • [44] An uncivilized behavior detection method based on improved ECO algorithm
    Wu, Hao
    Liang, Shasha
    Niu, Dan
    Ding, Li
    Hu, Yaocong
    Zhu, Xiaoci
    Xu, Ruohan
    Chen, Xisong
    2020 35TH YOUTH ACADEMIC ANNUAL CONFERENCE OF CHINESE ASSOCIATION OF AUTOMATION (YAC), 2020, : 843 - 847
  • [45] Research on flame detection method based on improved SSD algorithm
    Zhan, Huawei
    Pei, Xinyu
    Zhang, Tianhao
    Zhang, Linqing
    JOURNAL OF INTELLIGENT & FUZZY SYSTEMS, 2023, 45 (04) : 6501 - 6512
  • [46] A Bolt Pose Detection Method Based on Improved DOPE Algorithm
    Wang X.
    Mei Y.
    Zheng S.
    Beijing Ligong Daxue Xuebao/Transaction of Beijing Institute of Technology, 2023, 43 (10): : 1094 - 1104
  • [47] An Improved Moving Target Detection Method Based on Vibe Algorithm
    Shao, Xiaoqiang
    Chen, Xi
    Li, Kangle
    Lv, Zhichao
    Zhu, Hua
    2018 CHINESE AUTOMATION CONGRESS (CAC), 2018, : 1928 - 1931
  • [48] An improved method of edge detection based on the mean shift algorithm
    Wei, Laixing
    Liu, Bo
    Mou, Jiao
    7TH INTERNATIONAL SYMPOSIUM ON ADVANCED OPTICAL MANUFACTURING AND TESTING TECHNOLOGIES: OPTOELECTRONICS MATERIALS AND DEVICES FOR SENSING AND IMAGING, 2014, 9284
  • [49] An Improved Anomaly Detection Method Based on Fuzzy Association Rules
    Yang, Zifen
    PROCEEDINGS OF THE 2011 INTERNATIONAL CONFERENCE ON INFORMATICS, CYBERNETICS, AND COMPUTER ENGINEERING (ICCE2011), VOL 1: INTELLIGENT CONTROL AND NETWORK COMMUNICATION, 2011, 110 (01): : 441 - 447
  • [50] An Improved Anomaly Detection Method Based on Fuzzy Association Rules
    Yang, Zifen
    2010 INTERNATIONAL COLLOQUIUM ON COMPUTING, COMMUNICATION, CONTROL, AND MANAGEMENT (CCCM2010), VOL I, 2010, : 474 - 477