A clustered learning framework for host based intrusion detection in container environment

Jingfei Shen, Fanping Zeng, Weikang Zhang, Yufan Tao, Shengkun Tao · 2022 IEEE International Conference on Communications Workshops (ICC Workshops) · 2022

Container technology has been widely deployed in edge computing environments. Using the OS-level resource isolation and management, it can achieve incomparable high efficiency in contrast to the traditional virtual machine approach. However, recent studies have shown that the container environment is vulnerable to various security attacks. Furthermore, the highly customizable and dynamic change nature of the container exacerbated its vulnerability. In this paper, we propose a new anomaly detection framework combining cluster algorithm to improve anomaly detection efficiency in the edge computing environment that contains a large number of containers. It utilizes cluster algorithm to automatically identify containers that running the same application, and builds an anomaly detection model for each category separately. We investigated 8 real-world vulnerabilities from several frequently used applications and evaluated our framework on them. Experiment results show that our proposed framework can effectively identify containers built on the same application image without any manual labeling, reduce the FPR of anomaly detection from 0.61% to 0.09%, and increase TPR from 90.3% to 96.2% compared to the traditional method.

Read the paper · More papers on PaperTik