Protecting VNF services with smart online behavior anomaly detection method

被引:3
|
作者
Cheng, Yuxia [1 ]
Yao, Huijuan [2 ]
Wang, Yu [3 ]
Xiang, Yang [4 ]
Li, Hongpei [2 ]
机构
[1] Hangzhou Dianzi Univ, 1 Ave 2, Hangzhou, Zhejiang, Peoples R China
[2] Huawei Technol Co LTD, Shield Lab, Beijing, Peoples R China
[3] Guangzhou Univ, Guangzhou Higher Educ Mega Ctr, 230 Wai Huan Xi Rd, Guangzhou, Guangdong, Peoples R China
[4] Swinburne Univ Technol, John St, Hawthorn, Vic, Australia
关键词
NFV; Behavior model; HMM; Anomaly detection; OpenStack; INTRUSION DETECTION SYSTEM; HIDDEN MARKOV MODEL; PROBABILISTIC FUNCTIONS; NETWORK;
D O I
10.1016/j.future.2018.12.058
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Network Function Virtualization (NFV) is an emerging technology that allows network operators to deploy their Virtualized Network Functions (VNFs) on low-cost commodity servers in the cloud data center. The VNFs, such as virtual routers, firewalls etc., that typically control and transmit critical network packages, require strong security guarantees. However, detecting malicious or malfunctioning VNFs are challenging, as the behaviors of VNFs are dynamic and complex due to the changing network traffics in the cloud. In this paper, we propose a smart and efficient Hidden Markov Model based anomaly detection system (named vGuard) to protect online VNF services in the cloud. A general multivariate HMM model is proposed to profile the normal VNF behavior patterns. Using the VNF behavior model trained with normal observation sequences, vGuard can effectively detect abnormal behaviors online. vGuard is a general framework that can train different types of VNF behavior models. We implement the vGuard prototype in the OpenStack platform. Two types of VNF models, virtual router and virtual firewall, are trained using real normal network traffics in our experiment evaluation. A collection of abnormal attack cases are tested on the VNFs that showed the effectiveness of vGuard in detecting VNF behavior anomalies. (C) 2019 Elsevier B.V. All rights reserved.
引用
收藏
页码:265 / 276
页数:12
相关论文
共 50 条
  • [1] Unsupervised Anomaly Event Detection for VNF Service Monitoring using Multivariate Online Arima
    Schmidt, Florian
    Suri-Payer, Florian
    Gulenko, Anton
    Wallschlaeger, Marcel
    Acker, Alexander
    Kao, Odej
    2018 16TH IEEE INTERNATIONAL CONFERENCE ON CLOUD COMPUTING TECHNOLOGY AND SCIENCE (CLOUDCOM 2018), 2018, : 278 - 283
  • [2] Anomaly Detection Method for Online Discussion
    Krammer, Peter
    Habala, Ondrej
    Mojzis, Jan
    Hluchy, Ladislav
    Jurkovic, Marek
    16TH INTERNATIONAL CONFERENCE ON MOBILE SYSTEMS AND PERVASIVE COMPUTING (MOBISPC 2019),THE 14TH INTERNATIONAL CONFERENCE ON FUTURE NETWORKS AND COMMUNICATIONS (FNC-2019),THE 9TH INTERNATIONAL CONFERENCE ON SUSTAINABLE ENERGY INFORMATION TECHNOLOGY, 2019, 155 : 311 - 318
  • [3] Distributed Services for Pavement Anomaly Detection in Smart Roads
    Ficara, Annamaria
    Fazio, Maria
    Pellegrino, Orazio
    Ruggeri, Alessia
    Ruggeri, Armando
    Sollazzo, Giuseppe
    Bosurgi, Gaetano
    2024 IEEE INTERNATIONAL SYMPOSIUM ON MEASUREMENTS & NETWORKING, M & N 2024, 2024,
  • [4] Anomaly Detection for Smart Home Based on User Behavior
    Yamauchi, Masaaki
    Ohsita, Yuichi
    Murata, Masayuki
    Ueda, Kensuke
    Kato, Yoshiaki
    2019 IEEE INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS (ICCE), 2019,
  • [5] A Machine Learning based SLA-Aware VNF Anomaly Detection Method in Virtual Networks
    Hong, Jibum
    Park, Suhyun
    Yoo, Jae-Hyoung
    Hong, James Won-Ki
    11TH INTERNATIONAL CONFERENCE ON ICT CONVERGENCE: DATA, NETWORK, AND AI IN THE AGE OF UNTACT (ICTC 2020), 2020, : 1051 - 1056
  • [6] A New Smart Contract Anomaly Detection Method by Fusing Opcode and Source Code Features for Blockchain Services
    Duan, Li
    Yang, Liu
    Liu, Chunhong
    Ni, Wei
    Wang, Wei
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2023, 20 (04): : 4354 - 4368
  • [7] Online and Scalable Unsupervised Network Anomaly Detection Method
    Dromard, Juliette
    Roudiere, Gilles
    Owezarski, Philippe
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2017, 14 (01): : 34 - 47
  • [8] Practical Anomaly Detection over Multivariate Monitoring Metrics for Online Services
    Liu, Jinyang
    Yang, Tianyi
    Chen, Zhuangbin
    Su, Yuxin
    Feng, Cong
    Yang, Zengyin
    Lyu, Michael R.
    2023 IEEE 34TH INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING, ISSRE, 2023, : 36 - 45
  • [9] Scalable prediction-based online anomaly detection for smart meter data
    Liu, Xiufeng
    Nielsen, Per Sieverts
    INFORMATION SYSTEMS, 2018, 77 : 34 - 47
  • [10] An online log anomaly detection method based on grammar compression
    Gao, Yun
    Zhou, Wei
    Han, Ji-Zhong
    Meng, Dan
    Zhou, W. (zhouwei@iie.ac.cn), 1600, Science Press (37): : 73 - 86