首页> 外文OA文献 >CloudMon: a resource-efficient IaaS cloud monitoring system based on networked intrusion detection system virtual appliances
【2h】

CloudMon: a resource-efficient IaaS cloud monitoring system based on networked intrusion detection system virtual appliances

机译:CloudMon:基于网络入侵检测系统虚拟设备的资源高效的IaaS云监控系统

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

The networked intrusion detection system virtual appliance (NIDS-VA), also known as virtualized NIDS, plays an important role in the protection and safeguard of IaaS cloud environments. However, it is nontrivial to guarantee both of the performance of NIDS-VA and the resource efficiency of cloud applications because both are sharing computing resources in the same cloud environment. To overcome this challenge and trade-off, we propose a novel system, named CloudMon, which enables dynamic resource provision and live placement for NIDS-VAs in IaaS cloud environments. CloudMon provides two techniques to maintain high resource efficiency of IaaS cloud environments without degrading the performance of NIDS-VAs and other virtual machines (VMs). The first technique is a virtual machine monitor based resource provision mechanism, which can minimize the resource usage of a NIDS-VA with given performance guarantee. It uses a fuzzy model to characterize the complex relationship between performance and resource demands of a NIDS-VA and develops an online fuzzy controller to adaptively control the resource allocation for NIDS-VAs under varying network traffic. The second one is a global resource scheduling approach for optimizing the resource efficiency of the entire cloud environments. It leverages VM migration to dynamically place NIDS-VAs and VMs. An online VM mapping algorithm is designed to maximize the resource utilization of the entire cloud environment. Our virtual machine monitor based resource provision mechanism has been evaluated by conducting comprehensive experiments based on Xen hypervisor and Snort NIDS in a real cloud environment. The results show that the proposed mechanism can allocate resources for a NIDS-VA on demand while still satisfying its performance requirements. We also verify the effectiveness of our global resource scheduling approach by comparing it with two classic vector packing algorithms, and the results show that our approach improved the resource utilization of cloud environments and reduced the number of in-use NIDS-VAs and physical hosts.
机译:网络入侵检测系统虚拟设备(NIDS-VA),也称为虚拟化NIDS,在IaaS云环境的保护和保障中发挥着重要作用。但是,同时保证NIDS-VA的性能和云应用程序的资源效率并非易事,因为两者都在同一云环境中共享计算资源。为了克服这一挑战和权衡取舍,我们提出了一种名为CloudMon的新型系统,该系统可为IaaS云环境中的NIDS-VA提供动态资源提供和实时放置。 CloudMon提供了两种技术,可在不降低NIDS-VA和其他虚拟机(VM)性能的情况下保持IaaS云环境的高资源效率。第一种技术是基于虚拟机监视器的资源提供机制,该机制可以在给定性能保证的情况下最小化NIDS-VA的资源使用。它使用模糊模型来表征NIDS-VA的性能和资源需求之间的复杂关系,并开发了一种在线模糊控制器,以在变化的网络流量下自适应地控制NIDS-VA的资源分配。第二种是用于优化整个云环境的资源效率的全局资源调度方法。它利用VM迁移来动态放置NIDS-VA和VM。在线VM映射算法旨在最大化整个云环境的资源利用率。我们的基于虚拟机监视器的资源提供机制已通过在真实云环境中基于Xen虚拟机管理程序和Snort NIDS进行的全面实验进行了评估。结果表明,所提出的机制可以在满足其性能要求的同时为NIDS-VA分配资源。通过与两种经典的矢量打包算法进行比较,我们还验证了我们的全局资源调度方法的有效性,结果表明,该方法提高了云环境的资源利用率,并减少了正在使用的NIDS-VA和物理主机的数量。

著录项

  • 作者

    Li, Bo; Li, Jianxin; Liu, Lu;

  • 作者单位
  • 年度 2015
  • 总页数
  • 原文格式 PDF
  • 正文语种 en
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号