Thu Yein Win
Big data based security analytics for protecting virtualized infrastructures in cloud computing
Win, Thu Yein; Tianfield, Huaglory; Mair, Quentin
Authors
Huaglory Tianfield
Quentin Mair
Abstract
Virtualized infrastructure in cloud computing has become an attractive target for cyberattackers to launch advanced attacks. This paper proposes a novel big data based security analytics approach to detecting advanced attacks in virtualized infrastructures. Network logs as well as user application logs collected periodically from the guest virtual machines (VMs) are stored in the Hadoop Distributed File System (HDFS). Then, extraction of attack features is performed through graph-based event correlation and MapReduce parser based identification of potential attack paths. Next, determination of attack presence is performed through two-step machine learning, namely logistic regression is applied to calculate attack's conditional probabilities with respect to the attributes, and belief propagation is applied to calculate the belief in existence of an attack based on them. Experiments are conducted to evaluate the proposed approach using well-known malware as well as in comparison with existing security techniques for virtualized infrastructure. The results show that our proposed approach is effective in detecting attacks with minimal performance overhead.
Journal Article Type | Article |
---|---|
Acceptance Date | Jun 11, 2017 |
Online Publication Date | Jun 15, 2017 |
Publication Date | Mar 1, 2018 |
Deposit Date | May 12, 2021 |
Journal | IEEE Transactions on Big Data |
Publisher | Institute of Electrical and Electronics Engineers (IEEE) |
Peer Reviewed | Peer Reviewed |
Volume | 4 |
Issue | 1 |
Pages | 11-25 |
DOI | https://doi.org/10.1109/TBDATA.2017.2715335 |
Public URL | https://uwe-repository.worktribe.com/output/7360302 |
You might also like
PROTECT: Container process isolation using system call interception
(2017)
Presentation / Conference Contribution
Detection of malware and kernel-level rootkits in cloud computing environments
(2016)
Presentation / Conference Contribution
Virtualization security combining mandatory access control and virtual machine introspection
(2015)
Presentation / Conference Contribution
Detection of phishing websites using generative adversarial network
(2020)
Presentation / Conference Contribution
Digital twins in industry 4.0 cyber security
(2024)
Presentation / Conference Contribution
Downloadable Citations
About UWE Bristol Research Repository
Administrator e-mail: repository@uwe.ac.uk
This application uses the following open-source libraries:
SheetJS Community Edition
Apache License Version 2.0 (http://www.apache.org/licenses/)
PDF.js
Apache License Version 2.0 (http://www.apache.org/licenses/)
Font Awesome
SIL OFL 1.1 (http://scripts.sil.org/OFL)
MIT License (http://opensource.org/licenses/mit-license.html)
CC BY 3.0 ( http://creativecommons.org/licenses/by/3.0/)
Powered by Worktribe © 2024
Advanced Search