Malware Detection in Cloud Computing infrastructures

dc.contributor.authorNimith, Shetty M
dc.contributor.authorKishan V, Reddy
dc.contributor.authorKaushik C, Reddy
dc.date.accessioned2017-08-18T09:23:21Z
dc.date.available2017-08-18T09:23:21Z
dc.date.issued2017-08-18T09:23:21Z
dc.description.abstractCloud datacenters are beginning to be used for a range of always-on services across private, public and commercial domains. These need to be secure and resilient in the face of challenges that include cyber-attacks as well as component failures and mis-configurations. However, clouds have characteristics and intrinsic internal operational structures that impair the use of traditional detection systems. In particular, the range of beneficial properties offered by the cloud, such as service transparency and elasticity, introduce a number of vulnerabilities which are the outcome of its underlying virtualized nature. Moreover, an indirect problem lies with the cloud’s external dependency on IP networks, where their resilience and security has been extensively studied, but nevertheless remains an issue. The approach taken here relies on the principles and guidelines provided by an existing resilience framework. The underlying assumption is that in the near future, cloud infrastructures will be increasingly subjected to novel attacks and other anomalies, for which conventional signature based detection systems will be insufficiently equipped and therefore ineffective. Moreover, the majority of current signature-based schemes employ resource intensive deep packet inspection (DPI) that relies heavily on payload information where in many cases this payload can be encrypted, thus extra decryption cost is incurred. Our proposed scheme goes beyond these limitations since its operation does not depend on a-priori attack signatures and it does not consider payload information, but rather depends on per-flow meta-statistics as derived from packet header and volumetric information (i.e. counts of packets, bytes, etc.). Nonetheless, we argue that our scheme can synergistically operate with signature-based approaches on an online basis in scenarios were decryption is feasible and cost-effective. Overall, it is our goal to develop detection techniques that are specifically targeted at the cloud and integrate with the infrastructure itself in order to, not only detect, but also provide resilience through remediation. At the infrastructure level we consider: the elements that make up a cloud datacenter, i.e. cloud nodes, which are hardware servers that run a hypervisor in order to host a number of Virtual Machines (VMs); and network infrastructure elements that provide the connectivity within the cloud and connectivity to external service users.en_US
dc.identifier.urihttp://hdl.handle.net/123456789/8503
dc.language.isoenen_US
dc.subjectKaushik C Reddyen_US
dc.subjectMalware Detection in Cloud Computing infrastructuresen_US
dc.subject1nh13IS044en_US
dc.subjectISE Projects 2017en_US
dc.titleMalware Detection in Cloud Computing infrastructuresen_US
dc.typeOtheren_US
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
1NH13IS067.pdf
Size:
2.31 MB
Format:
Adobe Portable Document Format
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.79 KB
Format:
Item-specific license agreed upon to submission
Description:
Collections