首页> 外文会议>IEEE Conference on Communications and Network Security >Catching Falling Dominoes: Cloud Management-Level Provenance Analysis with Application to OpenStack
【24h】

Catching Falling Dominoes: Cloud Management-Level Provenance Analysis with Application to OpenStack

机译:赶上下降的Domino:适用于OpenStack的云管理级资源分析

获取原文

摘要

The dynamicity and complexity of clouds highlight the importance of automated root cause analysis solutions for explaining what might have caused a security incident. Most existing works focus on either locating malfunctioning clouds components, e.g., switches, or tracing changes at lower abstraction levels, e.g., system calls. On the other hand, a management-level solution can provide a big picture about the root cause in a more scalable manner. In this paper, we propose DOMINOCATCHER, a novel provenance-based solution for explaining the root cause of security incidents in terms of management operations in clouds. Specifically, we first define our provenance model to capture the interdependencies between cloud management operations, virtual resources and inputs. Based on this model, we design a framework to intercept cloud management operations and to extract and prune provenance metadata. We implement DOMINOCATCHER on OpenStack platform as an attached middleware and validate its effectiveness using security incidents based on real-world attacks. We also evaluate the performance through experiments on our testbed, and the results demonstrate that DOMINOCATCHER incurs insignificant overhead and is scalable for clouds.
机译:云的动态性和复杂性凸显了自动化根本原因分析解决方案对解释可能导致安全事件的原因的重要性。现有的大多数工作都集中在查找故障的云组件(例如交换机)或在较低的抽象级别(例如系统调用)跟踪更改。另一方面,管理级解决方案可以以更可扩展的方式提供有关根本原因的概览。在本文中,我们提出DOMINOCATCHER,这是一种基于源的新颖解决方案,用于从云中的管理操作方面解释安全事件的根本原因。具体来说,我们首先定义源模型,以捕获云管理操作,虚拟资源和输入之间的相互依赖性。基于此模型,我们设计了一个框架来拦截云管理操作并提取和修剪源元数据。我们在OpenStack平台上将DOMINOCATCHER作为附加的中间件实现,并使用基于实际攻击的安全事件来验证其有效性。我们还通过在试验台上进行实验来评估性能,结果表明DOMINOCATCHER不会产生太大的开销,并且可以针对云进行扩展。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号