{"title":"Anomaly Detection in IaaS Clouds","authors":"Frank Dölitzscher, M. Knahl, C. Reich, N. Clarke","doi":"10.1109/CloudCom.2013.57","DOIUrl":null,"url":null,"abstract":"Security is still a major concern in Cloud computing, especially the detection of nefarious use or abuse of cloud instances. One reason for this, is the ever-growing complexity and dynamic of the underlying system design and architecture. To be able to detect misuse of cloud instances, this work presents an anomaly detection system for Infrastructure as a Service Clouds. It is based on Cloud customers' usage behaviour analysis. Neural networks are used to analyse and learn the normal usage behaviour of Cloud customers, to then detect anomalies which could originate from a cloud security incident caused by an overtaken virtual machine. It increases transparency for Cloud customers about the security of their Cloud instances and supports the Cloud provider to detect misuse of their infrastructure. A simulation environment and an anomaly detection prototype get presented. Experiments validate the effectiveness of the proposed system.","PeriodicalId":198053,"journal":{"name":"2013 IEEE 5th International Conference on Cloud Computing Technology and Science","volume":"222 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2013-12-02","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"33","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2013 IEEE 5th International Conference on Cloud Computing Technology and Science","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CloudCom.2013.57","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 33
Abstract
Security is still a major concern in Cloud computing, especially the detection of nefarious use or abuse of cloud instances. One reason for this, is the ever-growing complexity and dynamic of the underlying system design and architecture. To be able to detect misuse of cloud instances, this work presents an anomaly detection system for Infrastructure as a Service Clouds. It is based on Cloud customers' usage behaviour analysis. Neural networks are used to analyse and learn the normal usage behaviour of Cloud customers, to then detect anomalies which could originate from a cloud security incident caused by an overtaken virtual machine. It increases transparency for Cloud customers about the security of their Cloud instances and supports the Cloud provider to detect misuse of their infrastructure. A simulation environment and an anomaly detection prototype get presented. Experiments validate the effectiveness of the proposed system.