BTDetect: An Insider Threats Detection Approach Based on Behavior Traceability for IaaS Environments

Li Lin, Shuang Li, Xuhui Lv, Bo Li · 2021

How to detect malicious insiders’ improper access to tenant data has become more crucial in IaaS cloud environment, especially with the cloud administrators gaining more control on customers’ virtual machines and data in reality. In this paper, we propose an insider threats detection approach based on behavior traceability called BTDetect. First, we analyze the service invocation interfaces of IaaS cloud environment, such as computing service, remote call, management implementation and virtualization management, and condense the complete process of cloud user behavior. Using tree-based modeling technique, a behavior-tree construction algorithm is proposed to construct the normal behavior tree that can describe various legal operations of cloud users. Second , we set up trace points of cloud service behavior on multi-layer cloud service APIs, then we collect information of each interface being invoked across multiple nodes. Third, we use underlying virtualization behavior keyword matching technology to match the collected behaviors with the user's normal behavior tree and then the malicious internal threat can be identified through tree-based integrity analysis. Finally, some experiments are conducted to evaluate the feasibility and veracity of the proposed method in Openstack platform. The results suggest that our method can not only identify internal threat but also have high recognition rate.

Read the paper · More papers on PaperTik