A Profile Based Network Intrusion Detection and Prevention System for Securing Cloud Environment

被引:26
|
作者
Gupta, Sanchika [1 ]
Kumar, Padam [1 ]
Abraham, Ajith [2 ,3 ]
机构
[1] Indian Inst Technol Roorkee, Dept Elect & Comp Engn, Roorkee 247667, Uttarakhand, India
[2] Sci Network Innovat & Res Excellence, Machine Intelligence Res Labs MIR Labs, Auburn, WA 98071 USA
[3] VSB Tech Univ Ostrava, Ctr Excellence IT4Innovat, Ostrava 70833, Czech Republic
关键词
All Open Access; Gold; Green;
D O I
10.1155/2013/364575
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cloud computing provides network based access to computing and data storage services on a pay per usage model. Cloud provides better utilization of resources and hence a reduced service access cost to individuals. Cloud services include software as a service, platform as a service, and infrastructure as a service. Cloud computing virtually and dynamically distributes the computing and data resources to a variety of users, based on their needs, with the use of virtualization technologies. As Cloud computing is a shared facility and is accessed remotely, it is vulnerable to various attacks including host and network based attacks (Brown 2012, and Grance 2009) and hence requires immediate attention. This paper identifies vulnerabilities responsible for well-known network based attacks on cloud and does a critical analysis on the security measures available in cloud environment. This paper focuses on a nonconventional technique for securing cloud network from malicious insiders and outsiders with the use of network profiling. With network profiling, a profile is created for each virtual machine (VM) in cloud that describes network behavior of each cloud user (an assigned VM). The behavior gathered is then used for determination (detection) of network attacks on cloud. The novelty of the approach lies in the early detection of network attacks with robustness and minimum complexity. The proposed technique can be deployed with minimal changes to existing cloud environment. An initial prototype implementation is verified and tested on private cloud with a fully functional implementation under progress.
引用
收藏
页数:12
相关论文
共 50 条
  • [41] Cloud Intrusion Detection System Based on SVM
    Alheeti K.M.A.
    Lateef A.A.A.
    Alzahrani A.
    Imran A.
    Al Dosary D.
    International Journal of Interactive Mobile Technologies, 2023, 17 (11) : 101 - 114
  • [42] Fast Localization Model of Network Intrusion Detection System for Enterprises Using Cloud Computing Environment
    Wang, Xingzhu
    MOBILE NETWORKS & APPLICATIONS, 2023, 28 (06): : 2191 - 2203
  • [43] Intrusion Detection System Using the G-ABC with Deep Neural Network in Cloud Environment
    Gulia N.
    Solanki K.
    Dalal S.
    Dhankhar A.
    Dahiya O.
    Salmaan N.U.
    Scientific Programming, 2023, 2023
  • [44] Efficacious Novel Intrusion Detection System for Cloud Computing Environment
    Rana, Pooja
    Batra, Isha
    Malik, Arun
    Ra, In-Ho
    Lee, Oh-Sung
    Hosen, A. S. M. Sanwar
    IEEE ACCESS, 2024, 12 : 99223 - 99239
  • [45] A Fingerprinting System Calls Approach for Intrusion Detection in a Cloud Environment
    Gupta, Sanchika
    Sardana, Anjali
    Kumar, Padam
    Abraham, Ajith
    2012 FOURTH INTERNATIONAL CONFERENCE ON COMPUTATIONAL ASPECTS OF SOCIAL NETWORKS (CASON), 2012, : 309 - 314
  • [46] An Improved Intrusion Detection System to Preserve Security in Cloud Environment
    Ghosh, Partha
    Biswas, Sumit
    Shakti, Shivam
    Phadikar, Santanu
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY AND PRIVACY, 2020, 14 (01) : 67 - 80
  • [47] Cloud Security: LKM and Optimal Fuzzy System for Intrusion Detection in Cloud Environment
    Shyla, S. Immaculate
    Sujatha, S. S.
    JOURNAL OF INTELLIGENT SYSTEMS, 2020, 29 (01) : 1626 - 1642
  • [48] Scalable and Dynamic Network Intrusion Detection and Prevention System
    Mahrach, Safaa
    Mjihil, Oussama
    Haqiq, Abdelkrim
    INNOVATIONS IN BIO-INSPIRED COMPUTING AND APPLICATIONS, IBICA 2017, 2018, 735 : 318 - 328
  • [49] A Comprehensive Network Intrusion Detection and Prevention System Architecture
    Mirpuryan, Minoo Sadat
    Tavizi, Tina
    Gharaee, Hossein
    2012 SIXTH INTERNATIONAL SYMPOSIUM ON TELECOMMUNICATIONS (IST), 2012, : 954 - 958
  • [50] Enterprise network intrusion detection and prevention system (ENIDPS)
    Akujuobi, C. M.
    Ampah, N. K.
    SENSORS, AND COMMAND, CONTROL, COMMUNICATIONS AND INTELLIGENCE (C31) TECHNOLOGIES FOR HOMELAND SECURITY AND HOMELAND DEFENSE VI, 2007, 6538