IHIDS: Introspection-based hybrid intrusion detection system in cloud environment

Amita Kashyap, Gautam Kumar, Sunita Jangir, Emmanuel S. Pilli, Preeti Mishra · 2017

Cloud Computing offers on demand services of infrastructure (servers, storage and network), platform (operating systems and databases) and software (applications) over the Internet on pay-as-you-use model. Security is of pre-eminent interest in this new era of computing as many e-commerce and social networking sites move their operations to the Cloud. One of the approaches to protect the Cloud Environment is to create a highly efficient system for Intrusion Detection which can handle both outsider as well as insider attacks. This paper proposes a misuse detection system at hypervisor layer to detect the inter-VM attacks in a virtual environment. It is named as Introspection-based Hybrid approach for Intrusion Detection System for Cloud (IHIDS). Virtual Machine Introspection (VMI) provides the needed system call sequences at the hypervisor layer. The proposed Hybrid model integrates information and evidence from system-wide process monitoring and the virtual network traffic analysis. The main focus of the paper is to detect intrusion at hypervisor layer by simultaneously analyzing network traffic and system calls. Anomalous behavior among tenant VMs caused because of Flooding and Port Scanning attacks is detected. The proposed technique is light-weight as there is no need to hold a large amount of data at any instance of time. It is efficient as well, in terms of complexity and resources it utilizes. It is validated against the dataset created in our lab and results are encouraging.

Read the paper · More papers on PaperTik