INTRUSION DETECTION PROCEDURE FOR CLOUD SERVERS USINGATTACKGRAPH MODEL

Authors

  • D.SUBA Research Scholar, Dept.of.Computer Science, Tamil University, Thanjavur-613010 Author
  • A.SENTHIL KUMAR Asst.professor, Dept.of.Computer science, Tamil University, Thanjavur-613010 Author

Keywords:

Cloud Security Alliance, Cloud Service Provider, Attack graph model, Infrastructure-as-a-Service.

Abstract

A recent Cloud Security Alliance (CSA) survey shows that among all security issues, abuse and nefarious useof cloud computing is considered as the top security threat, in which attackers can exploit vulnerabilities in clouds andutilize cloud system resources to deploy attacks. In traditional data centres, where system administrators have full control over the host machines, vulnerabilities can be detected and patched by the system administrator inacentralized manner. For better attack detection, this research work incorporates attack graph analytical proceduresfor the intrusion detection process. Our proposed solution can be deployed in an Infrastructure-as-a-Service (IaaS) cloud networking systems, and we assume that the Cloud Service Provider (CSP) is benign. An attack graphis amodelling tool to illustrate all possible multi-stage, multi-host attack paths that are crucial to understand threats andthen to decide appropriate countermeasures. In an attack graph, each node represents either preconditionconsequence of an exploit. The actions are not necessarily an active attack since normal protocol interactions canalso be used for attacks. Attack graph is helpful in identifying potential threats, possible attacks and knownvulnerable of all known abilities in a cloud system. Since the attack graph provides details of all knownvulnerabilities in the system and the connectivity information, we get a whole picture of current security situationof the system where we predict the possible threats and attacks by correlating detected events or activities. Intheanalysis stage, the AGM suggests the total no of files, file paths, uploaded date of file in the cloud Servers andfinally the file sizes. Thus any change or alternation in the above metrics is reflected in the graph as there is a chanceof intrusion Occurrence. Hence this research suggests, new techniques to counter against threat which occurs incloud server environment.

Downloads

Published

2016-09-30

Issue

Section

Articles