Network Intrusion Detection System as a Service on OpenStack Cloud

Chen Xu, Ruipeng Zhang, Mengjun Xie, Li Yang · 2019

Cloud computing has become a major computing paradigm and data processing approach in almost all sectors. To ensure normal business operation and data security, performing traffic monitoring and detecting suspicious network packets and possible network intrusions have become a daily job for tenant administrators. Using existing tools, a tenant administrator can set up a Network Intrusion Detection System (NIDS) on a virtual machine (VM) instance in the tenant and mirror the traffic from other instances in the tenant to the NIDS instance via Tap as a Service (TaaS) or a Switched Port Analyzer (SPAN) port. However, this type of mechanisms can consume significant resources (e.g., CPU and bandwidth) in the cloud environment. In this work, we propose a new lightweight approach, namely Network Intrusion Detection System as a Service (NIDSaaS), for OpenStack cloud. Our preliminary experimental results show that our NIDSaaS approach consumes much less CPU compared to the existing TaaS approach.

Read the paper · More papers on PaperTik