Danger Theory Based Hybrid Intrusion Detection Systems for Cloud Computing
Azuan Ahmad, Bharanidharan Shanmugam, Norbik Bashah Idris, Ganthan Narayana Samy, Sameer Hasan Albakri · International Journal of Computer and Communication Engineering · 2013
Cloud ComputingSecurity is a new implementation of computer technology and open a new research area and create a lot of opportunity of exploration.One of the new implementation in Cloud is Intrusion Detection System (IDS).There are problems with the implementation of existing IDS approach in normal environment.Traditional IDS need a lot of self maintenance and did not scale with the customer security requirements.The cost of maintaining and installing the traditional IDS is also a big consideration in implementing IDS in an organization.One of the solution of the problems in traditional IDS is by implementing it in Cloud environment.In Cloud, IDS can be managed centrally and can reduce the maintenance need to be done by a single company that use the IDS.The future IDS should come with reasonable cost, and reduced complexity with strong defensive mechanism.Thus, we propose an intrusion detection based on Software as a Service called Software as a Service Intrusion Detection Services (SaaSIDS) that not only for commercial solution, but also for open research communities.In this research, we focus on doing research on Software As A Service IDS (SaaSIDS) where traffic at different points of the network is sniffed and the interested packets would be transferred to the SaaSIDS for further inspection.The main engine of SaaSIDS is the hybrid analysis engine where the signature based engine and anomaly based engine which using Artificial Immune System (AIS) will work in parallel.The SaaSIDS is able to identify malicious activity and would generate appropriate alerts and notification accordingly.