CDDN: A concept drift driven virtual network attack detection framework in hypervisor-based environment

Arjun Singh, Gaurav Kothari, Preeti Mishra · 2024

Virtualization-layer has opened new doors for attacks and raised serious security concerns. The traditional intrusion detection mechanisms are less efficient in detecting emerging attacks in virtualization. The detection of evolving malicious activities is important to prevent the spread of any harmful operations, especially among co-located VMs. Moreover, the evolving behavior of the attacks may affect the decision boundaries of the static-trained machine learning models, leading to a ‘concept drift’ problem. In this paper, we have proposed a concept-drift driven virtual network security framework, called CDDN that detects malicious network activities by analyzing virtual machine (VM) traffic profile and provides a solution to the problem of concept drift. CDDN is deployed at the privilege domain of hypervisor and initially performs the network introspection, to capture the virtual network traffic of the monitored VM. The traffic is pre-processed and various important features are extracted. CDDN employs a combination of supervised and unsupervised machine learning techniques to distinguish between benign and attack network flows. In addition, it employs a drift detection method to identify drifted samples from the streaming data. Furthermore, incremental learning is implemented to update the model with evolving attack patterns, representing drift (representing drift).The approach has been validated with both publicly available and self-generated network attack datasets. The results seem to be promising.

Read the paper · More papers on PaperTik