DSEOM: A Framework for Dynamic Security Evaluation and Optimization of MTD in Container-Based Cloud

被引:29
|
作者
Jin, Hai [1 ]
Li, Zhi [1 ]
Zou, Deqing [1 ]
Yuan, Bin [1 ]
机构
[1] Huazhong Univ Sci & Technol, Big Data Secur Engn Res Ctr, Serv Comp Technol & Syst Lab, Cluster & Grid Comp Lab,Natl Engn Res Ctr Big Dat, Wuhan 430074, Peoples R China
关键词
Cloud computing; Containers; Security; Computer architecture; Complexity theory; Virtualization; Tools; Container; microservice; moving target defense; cloud computing; MOVING TARGET DEFENSE;
D O I
10.1109/TDSC.2019.2916666
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Due to the lightweight features, the combination of container technology and microservice architecture makes container-based cloud environment more efficient and agile than VM-based cloud environment. However, it also greatly amplifies the dynamism and complexity of the cloud environment and increases the uncertainty of security issues in the system concurrently. In this case, the effectiveness of defense mechanisms with fixed strategies would fluctuate as the updates occur in cloud environment. We refer this problem as effectiveness drift problem of defense mechanisms, which is particularly acute in the proactive defense mechanisms, such as moving target defense (MTD). To tackle this problem, we present DSEOM, a framework that can automatically perceive updates of container-based cloud environment, rapidly evaluate the effectiveness change of MTD and dynamically optimize MTD strategies. Specifically, we establish a multi-dimensional attack graphs model to formalize various complex attack scenarios. Combining with this model, we introduce the concept of betweenness centrality to effectively evaluate and optimize the implementation strategies of MTD. In addition, we present a series of security and performance metrics to quantify the effectiveness of MTD strategies in DSEOM. And we conduct extensive experiments to illustrate the existence of the effectiveness drift problem and demonstrate the usability and scalability of DSEOM.
引用
收藏
页码:1125 / 1136
页数:12
相关论文
共 50 条
  • [1] An Optimal Active Defensive Security Framework for the Container-Based Cloud with Deep Reinforcement Learning
    Li, Yuanbo
    Hu, Hongchao
    Liu, Wenyan
    Yang, Xiaohan
    [J]. ELECTRONICS, 2023, 12 (07)
  • [2] Dynamic Container-based Resource Management Framework of Spark Ecosystem
    Qureshi, Nawab Muhammad Faseeh
    Siddiqui, Isma Farah
    Abbas, Asad
    Bashir, Ali Kashif
    Choi, Keehyun
    Kim, Jaehyoun
    Shin, Dong Ryeol
    [J]. 2019 21ST INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY (ICACT): ICT FOR 4TH INDUSTRIAL REVOLUTION, 2019, : 522 - 526
  • [3] gEdge: A Container-Based Cloud-Edge Collaboration Framework for Heterogeneous Computing
    Wang, Yun
    Tang, Dong-Jie
    Guo, Kai-Cheng
    Qi, Zheng-Wei
    Guan, Hai-Bing
    [J]. Jisuanji Xuebao/Chinese Journal of Computers, 2024, 47 (08): : 1883 - 1900
  • [4] A priority-aware scheduling framework for heterogeneous workloads in container-based cloud
    Zhu, Lilu
    Huang, Kai
    Fu, Kun
    Hu, Yanfeng
    Wang, Yang
    [J]. APPLIED INTELLIGENCE, 2023, 53 (12) : 15222 - 15245
  • [5] A priority-aware scheduling framework for heterogeneous workloads in container-based cloud
    Lilu Zhu
    Kai Huang
    Kun Fu
    Yanfeng Hu
    Yang Wang
    [J]. Applied Intelligence, 2023, 53 : 15222 - 15245
  • [6] An optimal defensive deception framework for the container-based cloud with deep reinforcement learning
    Li, Huanruo
    Guo, Yunfei
    Sun, Penghao
    Wang, Yawen
    Huo, Shumin
    [J]. IET INFORMATION SECURITY, 2022, 16 (03) : 178 - 192
  • [7] Container Based On-Premises Cloud Security Framework
    Bhowmik, Soumya
    Bhanu, S. Mary Saira
    Rajendran, Balaji
    [J]. PROCEEDINGS OF THE 5TH INTERNATIONAL CONFERENCE ON INVENTIVE COMPUTATION TECHNOLOGIES (ICICT-2020), 2020, : 773 - 778
  • [8] Container-based Microservice Architecture for Cloud Applications
    Singh, Vindeep
    Peddoju, Sateesh K.
    [J]. 2017 IEEE INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND AUTOMATION (ICCCA), 2017, : 847 - 852
  • [9] Optimized Container-Based Process Execution in the Cloud
    Waibel, Philipp
    Yeshchenko, Anton
    Schulte, Stefan
    Mendling, Jan
    [J]. ON THE MOVE TO MEANINGFUL INTERNET SYSTEMS (OTM 2018), PT II, 2018, 11230 : 3 - 21
  • [10] Quantifying Cloud Elasticity with Container-based Autoscaling
    Tang, Xuxin
    Zhang, Fan
    Li, Xiu
    Khan, Samee U.
    Li, Zhijiang
    [J]. 2017 IEEE 15TH INTL CONF ON DEPENDABLE, AUTONOMIC AND SECURE COMPUTING, 15TH INTL CONF ON PERVASIVE INTELLIGENCE AND COMPUTING, 3RD INTL CONF ON BIG DATA INTELLIGENCE AND COMPUTING AND CYBER SCIENCE AND TECHNOLOGY CONGRESS(DASC/PICOM/DATACOM/CYBERSCI, 2017, : 853 - 860