首页> 外文期刊>IEEE transactions on dependable and secure computing >NICE: Network Intrusion Detection and Countermeasure Selection in Virtual Network Systems
【24h】

NICE: Network Intrusion Detection and Countermeasure Selection in Virtual Network Systems

机译:NICE:虚拟网络系统中的网络入侵检测和对策选择

获取原文
获取原文并翻译 | 示例

摘要

Cloud security is one of most important issues that has attracted a lot of research and development effort in past few years. Particularly, attackers can explore vulnerabilities of a cloud system and compromise virtual machines to deploy further large-scale Distributed Denial-of-Service (DDoS). DDoS attacks usually involve early stage actions such as multistep exploitation, low-frequency vulnerability scanning, and compromising identified vulnerable virtual machines as zombies, and finally DDoS attacks through the compromised zombies. Within the cloud system, especially the Infrastructure-as-a-Service (IaaS) clouds, the detection of zombie exploration attacks is extremely difficult. This is because cloud users may install vulnerable applications on their virtual machines. To prevent vulnerable virtual machines from being compromised in the cloud, we propose a multiphase distributed vulnerability detection, measurement, and countermeasure selection mechanism called NICE, which is built on attack graph-based analytical models and reconfigurable virtual network-based countermeasures. The proposed framework leverages OpenFlow network programming APIs to build a monitor and control plane over distributed programmable virtual switches to significantly improve attack detection and mitigate attack consequences. The system and security evaluations demonstrate the efficiency and effectiveness of the proposed solution.
机译:云安全是最重要的问题之一,在过去几年中吸引了许多研究和开发工作。尤其是,攻击者可以探索云系统的漏洞并破坏虚拟机,以部署更多的大规模分布式拒绝服务(DDoS)。 DDoS攻击通常涉及早期行动,例如多步骤利用,低频漏洞扫描以及将已识别的易受攻击的虚拟机破坏为僵尸,最后通过受感染的僵尸进行DDoS攻击。在云系统中,尤其是在基础架构即服务(IaaS)云中,僵尸探索攻击的检测非常困难。这是因为云用户可能会在其虚拟机上安装易受攻击的应用程序。为了防止易受攻击的虚拟机在云中受到威胁,我们提出了一种称为NICE的多阶段分布式漏洞检测,度量和对策选择机制,该机制建立在基于攻击图的分析模型和基于可重新配置的虚拟网络的对策之上。提出的框架利用OpenFlow网络编程API在分布式可编程虚拟交换机上构建监视和控制平面,从而显着改善攻击检测并减轻攻击后果。系统和安全评估证明了所提出解决方案的效率和有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号