Malware Detection in Cloud Computing infrastructures
Loading...
Files
Date
2017-08-18T09:23:21Z
Journal Title
Journal ISSN
Volume Title
Publisher
Abstract
Cloud datacenters are beginning to be used for a range of always-on services across
private, public and commercial domains. These need to be secure and resilient in the face of
challenges that include cyber-attacks as well as component failures and mis-configurations.
However, clouds have characteristics and intrinsic internal operational structures that impair the
use of traditional detection systems. In particular, the range of beneficial properties offered by
the cloud, such as service transparency and elasticity, introduce a number of vulnerabilities
which are the outcome of its underlying virtualized nature. Moreover, an indirect problem lies
with the cloud’s external dependency on IP networks, where their resilience and security has
been extensively studied, but nevertheless remains an issue.
The approach taken here relies on the principles and guidelines provided by an existing
resilience framework. The underlying assumption is that in the near future, cloud infrastructures
will be increasingly subjected to novel attacks and other anomalies, for which conventional
signature based detection systems will be insufficiently equipped and therefore ineffective.
Moreover, the majority of current signature-based schemes employ resource intensive deep
packet inspection (DPI) that relies heavily on payload information where in many cases this
payload can be encrypted, thus extra decryption cost is incurred. Our proposed scheme goes
beyond these limitations since its operation does not depend on a-priori attack signatures and it
does not consider payload information, but rather depends on per-flow meta-statistics as derived
from packet header and volumetric information (i.e. counts of packets, bytes, etc.). Nonetheless,
we argue that our scheme can synergistically operate with signature-based approaches on an
online basis in scenarios were decryption is feasible and cost-effective. Overall, it is our goal to
develop detection techniques that are specifically targeted at the cloud and integrate with the
infrastructure itself in order to, not only detect, but also provide resilience through remediation.
At the infrastructure level we consider: the elements that make up a cloud datacenter, i.e.
cloud nodes, which are hardware servers that run a hypervisor in order to host a number of
Virtual Machines (VMs); and network infrastructure elements that provide the connectivity
within the cloud and connectivity to external service users.
Description
Keywords
Kaushik C Reddy, Malware Detection in Cloud Computing infrastructures, 1nh13IS044, ISE Projects 2017