DistAppGaurd: Distributed Application Behaviour Profiling in Cloud-Based Environment

被引:0
|
作者
Ghorbani, Mohammad Mahdi [1 ]
Moghaddam, Fereydoun Farrahi [2 ]
Zhang, Mengyuan [3 ]
Pourzandi, Makan [2 ]
Kim Khoa Nguyen [1 ]
Cheriet, Mohamed [1 ]
机构
[1] Univ Quebec, Ste Foy, PQ, Canada
[2] Ericsson Secur Res, Toronto, ON, Canada
[3] Hong Kong Polytechn Univ, Hong Kong, Peoples R China
关键词
distributed behaviour profiling; anomaly detection; microservice; machine learning; autoencoder; INTRUSION DETECTION TECHNIQUES;
D O I
10.1145/3485832.3485907
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Today, Machine Learning (ML) techniques are increasingly used to detect abnormal behaviours of industrial applications. Since many of these applications are moving to the cloud environments, classical ML approaches are facing new challenges in accurately identifying abnormal behaviours due to the highly dynamic and heterogeneous nature of the cloud. In this paper, we propose a novel framework, DistAppGaurd, for profiling simultaneously the behaviour of all microservice components of a distributed application in the cloud. The framework can therefore, detect complex attacks that are not observable by monitoring a single process or a single microservice. DistAppGaurd utilizes the system calls executed by all the processes of an application to build a graph consisting of data exchanges among different application entities (e.g., processes and files) representing the behaviour of the application. This representation is then used by our novel miroservice-aware Autoencoder model to perform anomaly detection at runtime. The efficiency and feasibility of our approach is shown by implementing several different real-world attacks, which yields high detection rates (94%-97%) at 0.01% false alarm rate.
引用
收藏
页码:837 / 848
页数:12
相关论文
共 50 条
  • [1] A Cloud-based Immersive Learning Environment for Distributed Systems Algorithms
    Barve, Yogesh D.
    Patil, Prithviraj
    Gokhale, Aniruddha
    [J]. PROCEEDINGS 2016 IEEE 40TH ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE WORKSHOPS, VOL 1, 2016, : 754 - 763
  • [2] Cloud-Based Distributed Image Coding
    Song, Xiaodan
    Peng, Xiulian
    Xu, Jizheng
    Shi, Guangming
    Wu, Feng
    [J]. IEEE TRANSACTIONS ON CIRCUITS AND SYSTEMS FOR VIDEO TECHNOLOGY, 2015, 25 (12) : 1926 - 1940
  • [3] CLOUD-BASED DISTRIBUTED IMAGE CODING
    Song, Xiaodan
    Peng, Xiulian
    Xu, Jizheng
    Wu, Feng
    [J]. 2014 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING (ICIP), 2014, : 4802 - 4806
  • [4] Integrating Intelligent Electric Devices into Distributed Energy Resources in a Cloud-Based Environment
    Petersen, B.
    Winther, D.
    Pedersen, A.
    Poulsen, B.
    Traeholt, C.
    [J]. 2013 4TH IEEE/PES INNOVATIVE SMART GRID TECHNOLOGIES EUROPE (ISGT EUROPE), 2013,
  • [5] Design of a hybrid model for dynamic engagement behaviour analysis in a cloud-based environment
    Chen, You-Shyang
    Lin, Chien-Ku
    Chuang, Huan-Ming
    Cheng, Ming-Chang
    [J]. INTERNATIONAL JOURNAL OF AD HOC AND UBIQUITOUS COMPUTING, 2017, 25 (1-2) : 85 - 96
  • [6] Cloud-Based Application Whitelisting
    Hizver, Jennia
    Chiueh, Tzi-cker
    [J]. 2013 IEEE SIXTH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING (CLOUD 2013), 2013, : 636 - 643
  • [7] Cloud-based Architectures for Environment Monitoring
    Tovarnitchi, Vasile M.
    [J]. 2017 21ST INTERNATIONAL CONFERENCE ON CONTROL SYSTEMS AND COMPUTER SCIENCE (CSCS), 2017, : 708 - 714
  • [8] PADS: Design and Implementation of a Cloud-Based, Immersive Learning Environment for Distributed Systems Algorithms
    Barve, Yogesh D.
    Patil, Prithviraj
    Bhattacharjee, Anirban
    Gokhale, Aniruddha
    [J]. IEEE TRANSACTIONS ON EMERGING TOPICS IN COMPUTING, 2018, 6 (01) : 20 - 31
  • [9] Resource Allocation in Cloud-Based Distributed Cameras
    Agrawal, Bikash
    Surbiryala, Jayachander
    Rong, Chunming
    [J]. 2017 IEEE 6TH INTERNATIONAL CONGRESS ON BIG DATA (BIGDATA CONGRESS 2017), 2017, : 153 - 160
  • [10] A Distributed Cloud-based Service Recommendation System
    Ganchev, Ivan
    Ji, Zhanlin
    O'Droma, Mairtin
    [J]. 2015 INTERNATIONAL CONFERENCE ON COMPUTING AND NETWORK COMMUNICATIONS (COCONET), 2015, : 212 - 215