Detecting Anomalies Through Sequential Performance Analysis in Virtualized Environments
Charles F. Gonçalves, Daniel Sadoc Menasché, Alberto Avritzer, Nuno Antunes, Marco Paulo Amorim Vieira · IEEE Access · 2023
Virtualization enables Cloud Computing, allowing for server consolidation with cost reduction. It also introduces new challenges in terms of security and isolation, which are one of the deterrents in their adoption in critical systems. Virtualized systems tend to be very complex, and multi-tenancy is the norm, as the hypervisor manages the resources shared amongst virtual machines. This paper proposes a methodology that uses performance modeling for the detection of anomalies caused by security attacks in virtualized environments. Experiments are conducted to profile the system operation under normal conditions for its business transactions. The results are used to calibrate a performance model and to understand the impact of its parameters on the false positives probability. During operation, the system is monitored, and deviations are detected by applying a sequential analysis algorithm (the bucket algorithm). The methodology is evaluated using a representative cloud workload (TPCx-V), which was profiled during a set of executions. We consider resource exhaustion anomalies to emulate the effects of attacks affecting the performance of the system. The results show that our approach is able to successfully detect anomalies, with a low number of false positives, and spot possible residual effects on the system.