首页> 外文期刊>International journal of information privacy, security and integrity >ProvlntSec: a provenance cognition blueprint ensuring integrity and security for real life open source cloud
【24h】

ProvlntSec: a provenance cognition blueprint ensuring integrity and security for real life open source cloud

机译:ProvlntSec:一种来源识别蓝图,可确保现实生活中的开源云的完整性和安全性

获取原文
获取原文并翻译 | 示例
           

摘要

The distributed nature and growing demand for open source cloud makes the system an ideal target for malicious attacks and unauthorised file transfers. Requirements of provenance cognition scheme can come forward to solve the problem. However, such mechanisms of provenance detection has been considered to a limited extent for open source cloud computing. ProvlntSec is a novel mechanism that ensures effective collection of provenance information from a large pool of virtual machine (VM) instances on open source cloud platform. ProvlntSec captures critical system journals from VM instances and pattern matches those with predefined signatures to detect the presence of malicious activities. In addition, ProvlntSec identifies the Linux process trees to determine unauthorised file movements across different nodes. The experiments were executed in OpenStack Essex cloud environment running on real life system, and standard metrics were used to calculate the results. The obtained results show average precision values of 92.81% and 81.24% for malware detection and unauthorised file transfers respectively. At the same time, cumulative performance gains of 0.3991 and 8.77 are obtained. Upon comparison of the obtained results with benchmarks, ProvlntSec shows desirable gain in performance.
机译:分布式特性和对开源云的不断增长的需求使该系统成为恶意攻击和未经授权的文件传输的理想目标。可以提出出处识别方案的要求来解决该问题。然而,对于开源云计算,已经有限地考虑了这种来源检测机制。 ProvlntSec是一种新颖的机制,可确保从开源云平台上的大型虚拟机(VM)实例池中有效收集来源信息。 ProvlntSec可以从VM实例中捕获关键系统日志,并与具有预定义签名的日志进行模式匹配,以检测是否存在恶意活动。另外,ProvlntSec可以识别Linux进程树,以确定跨不同节点的未经授权的文件移动。实验在运行于现实生活系统上的OpenStack Essex云环境中执行,并使用标准指标计算结果。获得的结果显示,恶意软件检测和未经授权的文件传输的平均精度分别为92.81%和81.24%。同时,获得了0.3991和8.77的累积性能提升。通过将获得的结果与基准进行比较,ProvlntSec表现出了理想的性能提升。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号