High Impact Factor : 4.396 icon | Submit Manuscript Online icon |

PRIVACY PRESERVING AGAINST NETWORK INTRUSION DETECTION IN VIRTUAL NETWORK SYSTEM

Author(s):

SHRUTHI S , RNS INSTITUTE OF TECHNOLOGY

Keywords:

Network Security, Cloud Computing, Intrusion Detection, Attack Graph, Zombie Detection.

Abstract

Cloud security is one of most important issues that has attracted a lot of research and development effort in past few years. Particularly, attackers can explore vulnerabilities of a cloud system and compromise virtual machines to deploy further large-scale Distributed Denial-of-Service(DDoS). DDoS attacks usually involve early stage actions such as multi-step exploitation, low frequency vulnerability scanning, and compromising identified vulnerable virtual machines as zombies, and finally DDoS attacks through the compromised zombies. Within the cloud system, especially the Infrastructure-as-a-Service (IaaS) clouds, the detection of zombie exploration attacks is extremely difficult. This is because cloud users may install vulnerable applications on their virtual machines. To prevent vulnerable virtual machines from being compromised in the cloud, we propose a multi-phase distributed vulnerability detection, measurement, and countermeasure selection mechanism called NICE, which is built on attack graph based analytical models and reconfigurable virtual network-based countermeasures.

Other Details

Paper ID: IJSRDV2I5058
Published in: Volume : 2, Issue : 5
Publication Date: 01/08/2014
Page(s): 96-98

Article Preview

Download Article