A Network Function Virtualization Architecture for Automatic and Efficient Detection and Mitigation against Web Application Malware

被引:0
|
作者
Mauricio, Leopoldo [1 ]
Rubinstein, Marcelo [2 ]
机构
[1] Univ Fed Rio de Janeiro, Av Horacio Macedo,2030,Ctr Tecnol Sala H-301,Cidad, BR-21941598 Rio De Janeiro, RJ, Brazil
[2] Univ Estado Rio de Janeiro, Rio De Janeiro, RJ, Brazil
关键词
Security; Malware; Network Function Virtualization; Software -Defined Networking;
D O I
10.5753/jisa.2023.2847
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper proposes and implements a Network Function Virtualization (NFV) security architecture to provide automatic and efficient detection and mitigation against Web application malware. The mitigation is given by dynamically chaining a Virtual Security Function (VSF) to the data stream to block malicious exploitation traffic without affecting the benign traffic. We implement an NFV Security Controller (NFV-SC) that interacts with an Intrusion Detection System and a Web Application Firewall (WAF), both implemented as VSFs. We also implement a vulnerability scanner and a mechanism to automatically create rules in advance in the WAF-VSF when a security vulnerability is found in an application, even if no malicious traffic has attempted to exploit the flaw. In addition, it dynamically identifies and removes no longer used security rules to improve performance. We implement and evaluate our security proposal in the Open Platform for NFV (OPNFV). The evaluation results in our experimen-tal scenarios show that the NFV security architecture automatically blocks 99.12% of the HTTP malicious traffic without affecting 93.6% of the benign HTTP requests. Finally, we show that the number of rules in the WAF-VSF severely affects the latency to load HTTP response headers and that the number of redirection OpenFlow rules within Open vSwitches is not enough to significantly impact the end-user experience in modern web browser applications.
引用
收藏
页数:11
相关论文
共 50 条
  • [21] Unleashing GPUs for Network Function Virtualization: an open architecture based on Vulkan and Kubernetes
    Haavisto, Juuso
    Cholez, Thibault
    Riekki, Jukka
    PROCEEDINGS OF THE IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM 2022, 2022,
  • [22] Realizing Network Function Virtualization Management and Orchestration with Model Based Open Architecture
    Chen, YuLin
    Lambe, Mark
    Qin, Yinghua
    Chu, Wenjing
    2015 11TH INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE MANAGEMENT (CNSM), 2015, : 410 - 418
  • [23] Automatic Detection System of Web-based Malware for Management-type SaaS
    Jing Xu
    He Dongjian
    Zan Linsen
    Li Jianliang
    Yao Wang
    MATERIALS AND MANUFACTURING TECHNOLOGY, PTS 1 AND 2, 2010, 129-131 : 670 - +
  • [24] Application of Deep Learning Models for Real-Time Automatic Malware Detection
    Gutierrez, Rommel
    Villegas-Ch, William
    Naranjo Godoy, Lorena
    Mera-Navarrete, Aracely
    Lujan-Mora, Sergio
    IEEE ACCESS, 2024, 12 : 107742 - 107756
  • [25] Automatic Detection of Page Flow Defect in Web Application
    Wang, Jinding
    Jiang, Fan
    PROCEEDINGS OF 2009 INTERNATIONAL CONFERENCE ON INFORMATION, ELECTRONIC AND COMPUTER SCIENCE, VOLS I AND II, 2009, : 91 - 95
  • [26] REINFORCE: Achieving Efficient Failure Resiliency for Network Function Virtualization based Services
    Kulkarni, Sameer G.
    Liu, Guyue
    Ramakrishnan, K. K.
    Arumaithurai, Mayutan
    Wood, Timothy
    Fu, Xiaoming
    CONEXT'18: PROCEEDINGS OF THE 14TH INTERNATIONAL CONFERENCE ON EMERGING NETWORKING EXPERIMENTS AND TECHNOLOGIES, 2018, : 41 - 53
  • [27] Stochastic Scheduling towards Cost Efficient Network Function Virtualization in Edge Cloud
    Zeng, Deze
    Zhang, Jie
    Gu, Lin
    Guo, Song
    2018 15TH ANNUAL IEEE INTERNATIONAL CONFERENCE ON SENSING, COMMUNICATION, AND NETWORKING (SECON), 2018, : 397 - 405
  • [28] Improving Web Application Firewalls with Automatic Language Detection
    Nguyen T.-C.-H.
    Le-Nguyen M.-K.
    Le D.-T.
    Nguyen V.-H.
    Tôn L.-P.
    Nguyen-An K.
    SN Computer Science, 3 (6)
  • [29] Enabling Efficient Spatio-Temporal GPU Sharing for Network Function Virtualization
    Zeng, Deze
    Zhu, Andong
    Gu, Lin
    Li, Peng
    Chen, Quan
    Guo, Minyi
    IEEE TRANSACTIONS ON COMPUTERS, 2023, 72 (10) : 2963 - 2977
  • [30] A Neural Network-Based Approach for Cryptographic Function Detection in Malware
    Jia, Li
    Zhou, Anmin
    Jia, Peng
    Liu, Luping
    Wang, Yan
    Liu, Liang
    IEEE ACCESS, 2020, 8 : 23506 - 23521