首页> 外文期刊>CONCURRENCY PRACTICE & EXPERIENCE >CloudMon: a resource-efficient IaaS cloud monitoring system based on networked intrusion detection system virtual appliances
【24h】

CloudMon: a resource-efficient IaaS cloud monitoring system based on networked intrusion detection system virtual appliances

机译:CloudMon:基于网络入侵检测系统虚拟设备的资源高效的IaaS云监控系统

获取原文
获取原文并翻译 | 示例

摘要

The networked intrusion detection system virtual appliance (NIDS-VA), also known as virtualized NIDS, playsrnan important role in the protection and safeguard of IaaS cloud environments. However, it is nontrivial tornguarantee both of the performance of NIDS-VA and the resource efficiency of cloud applications because bothrnare sharing computing resources in the same cloud environment. To overcome this challenge and trade-off, wernpropose a novel system, named CloudMon, which enables dynamic resource provision and live placement forrnNIDS-VAs in IaaS cloud environments. CloudMon provides two techniques to maintain high resourcernefficiency of IaaS cloud environments without degrading the performance of NIDS-VAs and other virtualrnmachines (VMs). The first technique is a virtual machine monitor based resource provision mechanism, whichrncan minimize the resource usage of a NIDS-VA with given performance guarantee. It uses a fuzzy model torncharacterize the complex relationship between performance and resource demands of a NIDS-VA and developsrnan online fuzzy controller to adaptively control the resource allocation for NIDS-VAs under varying networkrntraffic. The second one is a global resource scheduling approach for optimizing the resource efficiency of thernentire cloud environments. It leverages VM migration to dynamically place NIDS-VAs and VMs. An onlinernVM mapping algorithm is designed to maximize the resource utilization of the entire cloud environment.rnOur virtual machine monitor based resource provision mechanism has been evaluated by conducting comprehensivernexperiments based on Xen hypervisor and Snort NIDS in a real cloud environment. The results showrnthat the proposed mechanism can allocate resources for a NIDS-VA on demand while still satisfying itsrnperformance requirements. We also verify the effectiveness of our global resource scheduling approach byrncomparing it with two classic vector packing algorithms, and the results show that our approach improvedrnthe resource utilization of cloud environments and reduced the number of in-use NIDS-VAs and physical hosts.
机译:网络入侵检测系统虚拟设备(NIDS-VA),也称为虚拟化NIDS,在IaaS云环境的保护和保障中起着重要的作用。但是,NIDS-VA的性能和云应用程序的资源效率都是不平凡的保证,因为两者都共享同一云环境中的计算资源。为了克服这一挑战和权衡取舍,我们提出了一个名为CloudMon的新型系统,该系统可在IaaS云环境中动态提供资源并实时放置NIDS-VA。 CloudMon提供了两种技术,可在不降低NIDS-VA和其他虚拟机(VM)性能的情况下保持IaaS云环境的高资源效率。第一种技术是基于虚拟机监视器的资源提供机制,它可以在给定性能保证的情况下最小化NIDS-VA的资源使用。它利用模糊模型刻画了NIDS-VA的性能与资源需求之间的复杂关系,并开发了在线模糊控制器来自适应地控制网络流量变化时NIDS-VA的资源分配。第二种是用于优化整个云环境的资源效率的全局资源调度方法。它利用VM迁移来动态放置NIDS-VA和VM。我们设计了一种在线VM映射算法,以最大程度地利用整个云环境。我们的基于虚拟机监视器的资源供应机制已通过在真实云环境中基于Xen虚拟机管理程序和Snort NIDS进行全面的实验进行了评估。结果表明,所提出的机制可以在满足其性能要求的同时,为NIDS-VA分配资源。通过与两种经典的向量打包算法进行比较,我们还验证了全局资源调度方法的有效性,结果表明,该方法提高了云环境的资源利用率,并减少了正在使用的NIDS-VA和物理主机的数量。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号