Network Intrusion Detection System as a Service in OpenStack Cloud

Chen Xu, Ruipeng Zhang, Mengjun Xie, Li Yang · 2020 International Conference on Computing, Networking and Communications (ICNC) · 2020

Network intrusion detection system (NIDS) is indispensable for cloud computing providers to detect ongoing cyber attacks and deter future ones in the cloud computing era. To help cloud users to secure their tenant networks inside a computing cloud, a tenant-based NIDS service model has been proposed where NIDS services are deployed as virtual instances inside tenants. However, this approach imposes significant virtualization overhead at the cost of tenants, and the NIDS provision process can be time-consuming. In this work, we present an innovative service model for OpenStack clouds called Network Intrusion Detection System as a Service (NIDSaaS). NIDSaaS enables on-demand, quick deployment and termination of NIDS, while maintaining lightweight overhead for cloud hosts and tenants. In addition, NIDSaaS provides a straightforward command line interface (CLI) so that cloud administrators can easily integrate NIDS with their tenants. We have implemented a prototype of NIDSaaS and evaluated it on a multi-node OpenStack testbed. Our evaluation results show that NIDSaaS outperforms existing VM-based NIDS service approach substantially in terms of service launch time and resource usage.

Read the paper · More papers on PaperTik