Malware Detection in Cloud Computing infrastructures

Loading...
Thumbnail Image
Files
Date
2017-08-18T09:23:21Z
Journal Title
Journal ISSN
Volume Title
Publisher
Abstract
Cloud datacenters are beginning to be used for a range of always-on services across private, public and commercial domains. These need to be secure and resilient in the face of challenges that include cyber-attacks as well as component failures and mis-configurations. However, clouds have characteristics and intrinsic internal operational structures that impair the use of traditional detection systems. In particular, the range of beneficial properties offered by the cloud, such as service transparency and elasticity, introduce a number of vulnerabilities which are the outcome of its underlying virtualized nature. Moreover, an indirect problem lies with the cloud’s external dependency on IP networks, where their resilience and security has been extensively studied, but nevertheless remains an issue. The approach taken here relies on the principles and guidelines provided by an existing resilience framework. The underlying assumption is that in the near future, cloud infrastructures will be increasingly subjected to novel attacks and other anomalies, for which conventional signature based detection systems will be insufficiently equipped and therefore ineffective. Moreover, the majority of current signature-based schemes employ resource intensive deep packet inspection (DPI) that relies heavily on payload information where in many cases this payload can be encrypted, thus extra decryption cost is incurred. Our proposed scheme goes beyond these limitations since its operation does not depend on a-priori attack signatures and it does not consider payload information, but rather depends on per-flow meta-statistics as derived from packet header and volumetric information (i.e. counts of packets, bytes, etc.). Nonetheless, we argue that our scheme can synergistically operate with signature-based approaches on an online basis in scenarios were decryption is feasible and cost-effective. Overall, it is our goal to develop detection techniques that are specifically targeted at the cloud and integrate with the infrastructure itself in order to, not only detect, but also provide resilience through remediation. At the infrastructure level we consider: the elements that make up a cloud datacenter, i.e. cloud nodes, which are hardware servers that run a hypervisor in order to host a number of Virtual Machines (VMs); and network infrastructure elements that provide the connectivity within the cloud and connectivity to external service users.
Description
Keywords
Kaushik C Reddy, Malware Detection in Cloud Computing infrastructures, 1nh13IS044, ISE Projects 2017
Citation
Collections