Virtual Host based Intrusion Detection System for Cloud
Manthira Moorthy S, M. Rajeswari, Rajiv Gandhi Salai · 2014
Cloud computing is an internet or intranet based computing, where infrastructure, information and Application are provisioned based on demand. The major breach in cloud is its security due to its huge extends of resources available in it. The major threats are data loss or leakage and hijacking. This paper presents Cloud Intrusion Detection Data Sets (CIDD) and virtual host based Intrusion Detection System. CIDD contains attack signatures based on port that are opened in cloud for communications, The signatures are prepared manually and scored using common vulnerability scoring system. Genetic Algorithm is the technique applied for generating rules from existing datasets. Large set of rules can be generated for intrusion detection by mean of genetic operation. Keyword- Cloud computing, Cloud security, Intruder, Cloud Intrusion Detection Datasets, Genetic Algorithm. I. INTRODUCTION Cloud Computing is the latest trend in computing. Cloud Computing provides computing resources that are delivered as a service over internet. Cloud consists of hardware and software resources made available on the internet. Anyone can easily provide, manage and sustain cloud resources for a fraction of cost. Due to enormous amount of storage, backup and restore facility more number of people and organisations have moved to cloud. So there is a critical need for secure data storage and secure access in the cloud. The Test-bed environment used in this paper is Cloud Stack with KVM hypervisor. Cloud Stack is an open source cloud computing tool for creating, managing, and deploying cloud infrastructure and services. It uses existing hypervisors such as KVM, vSPhere and Xenserver for virtualization. In Cloud based intrusion detection, anomaly-based approaches in particular suffer from accurate evaluation, comparison, and deployment which originates from the scarcity of adequate datasets. Many such datasets are heavily anonymized and do not reflect Cloud, These deficiencies are primarily the reasons why a perfect dataset is yet to exist for cloud. Here we proposes Cloud intrusion datasets which are prepared base on ports that are opened in cloud stack that are opened in cloud for communication. The Ports opened in Cloud Stack Components for communication are given in TABLE I. Cloud stack installation consists of two machines, one machine running the Management Server and another machine running KVM hypervisor. The traffic coming into the cloud stack should be monitored by means of IDS for malicious activities or policy violation. As traffic flow to hypervisor only through management server both management server and KVM hypervisor are considered as single host virtually. IDS is developed to monitor the traffic to entire host. Hence it is called as Virtual Host based Intrusion Detection.