A Profile Based Network Intrusion Detection and Prevention System for Securing Cloud Environment

被引:26
|
作者
Gupta, Sanchika [1 ]
Kumar, Padam [1 ]
Abraham, Ajith [2 ,3 ]
机构
[1] Indian Inst Technol Roorkee, Dept Elect & Comp Engn, Roorkee 247667, Uttarakhand, India
[2] Sci Network Innovat & Res Excellence, Machine Intelligence Res Labs MIR Labs, Auburn, WA 98071 USA
[3] VSB Tech Univ Ostrava, Ctr Excellence IT4Innovat, Ostrava 70833, Czech Republic
关键词
All Open Access; Gold; Green;
D O I
10.1155/2013/364575
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cloud computing provides network based access to computing and data storage services on a pay per usage model. Cloud provides better utilization of resources and hence a reduced service access cost to individuals. Cloud services include software as a service, platform as a service, and infrastructure as a service. Cloud computing virtually and dynamically distributes the computing and data resources to a variety of users, based on their needs, with the use of virtualization technologies. As Cloud computing is a shared facility and is accessed remotely, it is vulnerable to various attacks including host and network based attacks (Brown 2012, and Grance 2009) and hence requires immediate attention. This paper identifies vulnerabilities responsible for well-known network based attacks on cloud and does a critical analysis on the security measures available in cloud environment. This paper focuses on a nonconventional technique for securing cloud network from malicious insiders and outsiders with the use of network profiling. With network profiling, a profile is created for each virtual machine (VM) in cloud that describes network behavior of each cloud user (an assigned VM). The behavior gathered is then used for determination (detection) of network attacks on cloud. The novelty of the approach lies in the early detection of network attacks with robustness and minimum complexity. The proposed technique can be deployed with minimal changes to existing cloud environment. An initial prototype implementation is verified and tested on private cloud with a fully functional implementation under progress.
引用
收藏
页数:12
相关论文
共 50 条
  • [21] Intrusion Detection and Prevention using Honeypot Network for Cloud Security
    Negi, Poorvika Singh
    Garg, Aditya
    Lal, Roshan
    PROCEEDINGS OF THE CONFLUENCE 2020: 10TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING, DATA SCIENCE & ENGINEERING, 2020, : 129 - 132
  • [22] The Research of Intrusion Detection System in Cloud Computing Environment
    Wang, Huaibin
    Zhou, Haiyun
    ADVANCES IN MULTIMEDIA, SOFTWARE ENGINEERING AND COMPUTING, VOL 1, 2011, 128 : 45 - 49
  • [23] BNID: A Behavior-based Network Intrusion Detection at Network-Layer in Cloud Environment
    Ghanshala, Kamal Kumar
    Mishra, Preeti
    Joshi, R. C.
    Sharma, Sachin
    2018 FIRST INTERNATIONAL CONFERENCE ON SECURE CYBER COMPUTING AND COMMUNICATIONS (ICSCCC 2018), 2018, : 100 - 105
  • [24] Intelligent Intrusion Detection System for Private Cloud Environment
    Muthukumar, B.
    Rajendran, Praveen Kumar
    SECURITY IN COMPUTING AND COMMUNICATIONS (SSCC 2015), 2015, 536 : 54 - 65
  • [25] Enhanced intrusion detection and prevention system on cloud environment using hybrid classification and OTS generation
    Balamurugan, V.
    Saravanan, R.
    CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2019, 22 (Suppl 6): : 13027 - 13039
  • [26] FCM-SVM based intrusion detection system for cloud computing environment
    Jaber, Aws Naser
    Ul Rehman, Shafiq
    CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2020, 23 (04): : 3221 - 3231
  • [27] IHIDS: Introspection-Based Hybrid Intrusion Detection System in Cloud Environment
    Kashyap, Amita
    Kumar, G. Sravan
    Jangir, Sunita
    Pilli, Emmanuel S.
    Mishra, Preeti
    2017 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATIONS AND INFORMATICS (ICACCI), 2017, : 687 - 693
  • [28] Enhanced intrusion detection and prevention system on cloud environment using hybrid classification and OTS generation
    V. Balamurugan
    R. Saravanan
    Cluster Computing, 2019, 22 : 13027 - 13039
  • [29] A Network-based Internet Worm Intrusion Detection and Prevention System
    Wattanapongsakorn, N.
    Wonghirunsombat, E.
    Assawaniwed, T.
    Hanchana, V.
    Srakaew, S.
    Charnsripinyo, C.
    2013 INTERNATIONAL CONFERENCE ON IT CONVERGENCE AND SECURITY (ICITCS), 2013,
  • [30] Securing Fog-to-Things Environment Using Intrusion Detection System Based On Ensemble Learning
    Illy, Poulmanogo
    Kaddoum, Georges
    Moreira, Christian Miranda
    Kaur, Kuljeet
    Garg, Sahil
    2019 IEEE WIRELESS COMMUNICATIONS AND NETWORKING CONFERENCE (WCNC), 2019,