Please use this identifier to cite or link to this item: https://hdl.handle.net/1959.11/57152
Title: Out-VM monitoring for malicious network packet detection in cloud
Contributor(s): Mishra, Preeti (author); Pilli, Emmanuel S (author); Varadharajan, Vijay (author); Tupakula, Udaya  (author)orcid 
Publication Date: 2017
DOI: 10.1109/ISEASP.2017.7976995
Handle Link: https://hdl.handle.net/1959.11/57152
Abstract: 

Cloud security is one of the biggest challenge in today's technological world. Researchers have proposed some solutions for cloud security. Virtual Machine (VM)-level solutions are configured and controlled at VM. They are less robust and can be easily subverted by attackers. In this paper, we propose an out-VM monitoring security approach named as Malicious Network Packet Detection (MNPD) which monitors the VMs from outside at both network and virtualization layer in cloud environment. MNPD performs the behavioral analysis of network traffic at Cloud Networking Server (CNS); providing primary defense from intrusions at network level. MNPD does the VM traffic validation at hypervisor of Cloud Compute Server (CCoS) to detect spoofing attacks, originated from VMs. The non-spoofed packets are further analyzed using behavior analysis of network traffic to detect any abnormality in the virtual traffic; providing second level of defense from intrusions at virtualization level. MNPD employs statistical learning technique (Random Forest) with ensemble of feature selection approach to learn the behavior of traffic patterns. MNPD does not involve overhead incurred in monitoring extensive memory writes or instruction-level traces. It is a more secure solution to detect attacks which never pass through physical interface and hence not detected by traditional IDS. The proposed approach has been validated with latest datasets (UNSW-NB and ITOC) and results seem to be promising.

Publication Type: Conference Publication
Conference Details: 2017 ISEA Asia Security and Privacy (ISEASP), Surat, India, 29th January - 1st February, 2017
Source of Publication: ISEA Asia Security & Privacy Conference 2017, p. 1-10, p. 1-10
Publisher: Institute of Electrical and Electronics Engineers
Place of Publication: Piscataway, New Jersey, United States of America
Fields of Research (FoR) 2020: 460407 System and network security
Socio-Economic Objective (SEO) 2020: 220405 Cybersecurity
Peer Reviewed: Yes
HERDC Category Description: E1 Refereed Scholarly Conference Publication
Publisher/associated links: https://ieeexplore.ieee.org/document/7976995/authors#authors
WorldCat record: https://www.worldcat.org/search?q=978-1-5090-5943-0
Appears in Collections:Conference Publication
School of Science and Technology

Files in This Item:
2 files
File Description SizeFormat 
Show full item record

SCOPUSTM   
Citations

24
checked on Oct 19, 2024
Google Media

Google ScholarTM

Check

Altmetric


Items in Research UNE are protected by copyright, with all rights reserved, unless otherwise indicated.