Ab-HIDS: An anomaly-based host intrusion detection system using frequency of N-gram system call features and ensemble learning for containerized environment

被引:0
|
作者
Joraviya, Nidhi [1 ]
Gohil, Bhavesh N. [1 ]
Rao, Udai Pratap [2 ]
机构
[1] Sardar Vallabhbhai Natl Inst Technol, Dept Comp Sci & Engn, Surat, Gujarat, India
[2] Natl Inst Technol Patna, Dept Comp Sci & Engn, Patna, India
来源
关键词
anomaly detection system; cloud computing; containerized environment; ensemble machine learning; host intrusion detection system; system call analysis;
D O I
10.1002/cpe.8249
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Cloud's operating-system-level virtualization has introduced a new phase of lightweight virtualization through containers. The architecture of cloud-native and microservices-based application development strongly advocates for the use of containers due to their swift and convenient deployment capabilities. However, the security of applications within containers is important, as malicious or vulnerable content could jeopardize the container and the host system. This vulnerability also extends to neighboring containers and may compromise data integrity and confidentiality. The article focuses on developing an intrusion detection system tailored to containerized cloud environments by identifying system call analysis techniques and also proposes an anomaly-based host intrusion detection system (Ab-HIDS). This system employs the frequency of N-grams system calls as distinctive features. To enhance performance, two ensemble learning models, namely voting-based ensemble learning and XGBoost ensemble learning, are employed for training and testing the data. The proposed system is evaluated using the Leipzig Intrusion Detection Data Set (LID-DS), demonstrating substantial performance compared to existing state-of-the-art methods. Ab-HIDS is validated for class imbalance using the imbalance ratio and synthetic minority over-sampling technique methods. Our system achieved significant improvements in detection accuracy with 4% increase for the voting-based ensemble model and 6% increase for the XGBoost ensemble model. Additionally, we observed reductions in the false positive rate by 0.9% and 0.8% for these models, respectively, compared to existing state-of-the-art methods. These results illustrate the potential of our proposed approach in improving security measures within containerized environments.
引用
收藏
页数:21
相关论文
共 50 条
  • [1] Host Based Intrusion Detection System Using Frequency Analysis of N-Gram Terms
    Subba, Basant
    Biswas, Santosh
    Karmakar, Sushata
    TENCON 2017 - 2017 IEEE REGION 10 CONFERENCE, 2017, : 2006 - 2011
  • [2] DL-HIDS: deep learning-based host intrusion detection system using system calls-to-image for containerized cloud environment
    Joraviya, Nidhi
    Gohil, Bhavesh N.
    Rao, Udai Pratap
    JOURNAL OF SUPERCOMPUTING, 2024, 80 (09): : 12218 - 12246
  • [3] Host anomaly detection performance analysis based on system call of NeuroFuzzy using Soundex algorithm and N-gram technique
    Cha, BR
    2005 Systems Communications, Proceedings: ICW 2005, WIRELESS TECHNOLOGIES; ICHSN 2005, HIGH SPEED NETWORKS; ICMCS 2005, MULTIMEDIA COMMUNICATIONS SYSTEMS; SENET 2005, SENSOR NETWORKS, 2005, : 116 - 121
  • [4] An anomaly-based Network Intrusion Detection System using Deep learning
    Nguyen Thanh Van
    Tran Ngoc Thinh
    Le Thanh Sach
    2017 INTERNATIONAL CONFERENCE ON SYSTEM SCIENCE AND ENGINEERING (ICSSE), 2017, : 210 - 214
  • [5] HIDS: A host based intrusion detection system for cloud computing environment
    Deshpande P.
    Sharma S.C.
    Peddoju S.K.
    Junaid S.
    Deshpande, Prachi (deprachi3@gmail.com), 2018, Springer (09) : 567 - 576
  • [6] Anomaly-Based Intrusion Detection Using Machine Learning: An Ensemble Approach
    Lalduhsaka R.
    Bora N.
    Khan A.K.
    International Journal of Information Security and Privacy, 2022, 16 (01):
  • [7] Formulating ensemble mobile malware detection through n-gram system call sequence features
    Ariff, Nor Azman Mat
    Mas'ud, Mohd Zaki
    Ahmad, Amizah Aida
    Bahaman, Nazrulazhar
    Hamid, Erman
    PROCEEDINGS OF INNOVATIVE RESEARCH AND INDUSTRIAL DIALOGUE 2018 (IRID'18), 2019, : 218 - 219
  • [8] Anomaly Based Host Intrusion Detection System Using Semantic Based System Call Patterns
    Anandapriya, M.
    Lakshmanan, B.
    PROCEEDINGS OF 2015 IEEE 9TH INTERNATIONAL CONFERENCE ON INTELLIGENT SYSTEMS AND CONTROL (ISCO), 2015,
  • [9] Anomaly-based Network Intrusion Detection using Ensemble Machine Learning Approach
    Das, Abhijit
    Pramod
    Sunitha, B. S.
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2022, 13 (02) : 635 - 645
  • [10] Advanced Anomaly Intrusion Detection Technique For Host Based System Using System Call Patterns
    Maske, Sandeep Ankush
    Parvat, Thaksen. J.
    2016 INTERNATIONAL CONFERENCE ON INVENTIVE COMPUTATION TECHNOLOGIES (ICICT), VOL 2, 2016, : 441 - 444