ContainerGuard: A Real-Time Attack Detection System in Container-Based Big Data Platform

被引:20
|
作者
Wang, Yulong [1 ]
Wang, Qixu [1 ]
Chen, Xingshu [1 ]
Chen, Dajiang [2 ,3 ]
Fang, Xiaojie [4 ]
Yin, Mingyong [5 ]
Zhang, Ning [6 ]
机构
[1] Sichuan Univ, Sch Cyber Sci & Engn, Chengdu 610065, Peoples R China
[2] Univ Elect Sci & Technol China, Sch Informat & Software Engn, Chengdu 610054, Peoples R China
[3] Peng Cheng Lab, Shenzhen 518055, Peoples R China
[4] Harbin Inst Technol, Dept Elect & Informat Engn, Harbin 150001, Peoples R China
[5] China Acad Engn Phys, Inst Comp Applicat, Mianyang 621900, Sichuan, Peoples R China
[6] Univ Windsor, Dept Elect & Comp Engn, Windsor, ON N9B 3P4, Canada
基金
中国国家自然科学基金;
关键词
Containers; Big Data; Process control; Side-channel attacks; Kernel; Security; Hardware; Anomaly detection; big data platform security; container; meltdown and spectre; variational autoencoder (VAE); SIDE-CHANNEL ATTACKS; SPARK;
D O I
10.1109/TII.2020.3047416
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As a lightweight, flexible, and high-performance operating system virtualization, containers are used to speed up the big data platform. However, due to the imperfection of the resource isolation mechanism and the property of shared kernel, the meltdown and spectre attacks can lead to information leakage of kernel space and coresident containers. In this article, a noise-resilient and real-time detection system, named ContainerGuard, is proposed to detect meltdown and spectre attacks in the container-based big data platform. ContainerGuard uses a nonintrusive manner to collect lifecycle multivariate time-series performance event data of processes in containers and then uses ensemble of variational autoencoders as generative neural networks to learn the robust representations of normal patterns. Therefore, ContainerGuard meets the urgent need for information protection in the container-based big data platform. Our evaluations using real-world datasets show that ContainerGuard achieves excellent detection performance and only introduces about 4.5% of running performance overhead to the platform.
引用
收藏
页码:3327 / 3336
页数:10
相关论文
共 50 条
  • [21] Real-time intelligent big data processing: technology, platform, and applications
    Tongya Zheng
    Gang Chen
    Xinyu Wang
    Chun Chen
    Xingen Wang
    Sihui Luo
    Science China Information Sciences, 2019, 62
  • [22] Real-time analysis of flow data for network attack detection
    Muenz, Gerhard
    Carle, Georg
    2007 10TH IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT (IM 2009), VOLS 1 AND 2, 2007, : 100 - +
  • [23] Real-time intelligent big data processing: technology, platform, and applications
    Zheng, Tongya
    Chen, Gang
    Wang, Xinyu
    Chen, Chun
    Wang, Xingen
    Luo, Sihui
    SCIENCE CHINA-INFORMATION SCIENCES, 2019, 62 (08)
  • [24] Real-time intelligent big data processing:technology, platform, and applications
    Tongya ZHENG
    Gang CHEN
    Xinyu WANG
    Chun CHEN
    Xingen WANG
    Sihui LUO
    ScienceChina(InformationSciences), 2019, 62 (08) : 102 - 113
  • [25] Real-time Detection of Anomalies on Performance Data of Container Virtualization Platforms
    Erboy, Mehmet Onur
    Aktas, Mehmet S.
    Tuzun, Hakan
    Unal, Engin
    2020 5TH INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND ENGINEERING (UBMK), 2020, : 198 - 202
  • [26] Big Data Real-time Processing Based on Storm
    Yang, Wenjie
    Liu, Xingang
    Zhang, Lan
    Yang, Laurence T.
    2013 12TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2013), 2013, : 1784 - 1787
  • [27] The system security enhancement with real-time attack detection and analysis
    Zhu, S
    2001 INTERNATIONAL CONFERENCES ON INFO-TECH AND INFO-NET PROCEEDINGS, CONFERENCE A-G: INFO-TECH & INFO-NET: A KEY TO BETTER LIFE, 2001, : E66 - E71
  • [28] Real-time big data processing for anomaly detection: A Survey
    Habeeb, Riyaz Ahamed Ariyaluran
    Nasaruddin, Fariza
    Gani, Abdullah
    Hashem, Ibrahim Abaker Targio
    Ahmed, Ejaz
    Imran, Muhammad
    INTERNATIONAL JOURNAL OF INFORMATION MANAGEMENT, 2019, 45 : 289 - 307
  • [29] Unsupervised Network Anomaly Detection in Real-Time on Big Data
    Dromard, Juliette
    Roudiere, Gilles
    Owezarski, Philippe
    NEW TRENDS IN DATABASES AND INFORMATION SYSTEMS (ADBIS 2015), 2015, 539 : 197 - 206
  • [30] Real-time Online Detection Method for Web Attack Based on Flow Data Analysis
    Tian, Jian-wei
    Zhu, Hong-yu
    Li, Xi
    Tian, Zhen
    PROCEEDINGS OF 2018 IEEE 9TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING AND SERVICE SCIENCE (ICSESS), 2018, : 991 - 994