CIADL: cloud insider attack detector and locator on multi-tenant network isolation: an OpenStack case study

被引:0
|
作者
Jing Zhan
Xudong Fan
Jin Han
Yaqi Gao
Xiaoqing Xia
Qian Zhang
机构
[1] Beijing University of Technology,College of Computer Science, Faculty of Information Technology
[2] Beijing University of Technology,Beijing Key Laboratory of Trusted Computing
[3] Beijing University of Technology,National Engineering Laboratory for Critical Technologies of Information Security Classified Protection
关键词
Cloud computing; Multi-tenant network isolation; Insider attack detection;
D O I
暂无
中图分类号
学科分类号
摘要
In cloud networks, edging network virtualization technology is widely adopted to protect tenants with isolated networks mainly from threats inside the cloud. However, since tenants completely rely on cloud service provider’s service interface to be aware of their current network policy, malicious admin alone or with concluded tenants is/are fully capable of acquiring any target tenant network data by attacking corresponding policies stored and enforced on the edging end hosts without tenants knowing. Therefore, this paper presents cloud insider attack detector and locator (CIADL) on multi-tenant network isolation for OpenStack. We propose an insider attack threat model with attack category. A layered state model based constructing and attack detection methods are also proposed, enabling efficient policy confliction detection between expected policy on central node and enforcing policy on end hosts. Along with a threat locating method with fine granularity of device policy rules for recovery purpose. We implements the proof of concept system of CIADL, and the experiments and analysis show our method can cover all attack types defined in threat model with low overheads, and scales well with network and policy size and attack number increase. Compared to existing work model with VM–VM state, CIADL state model with NET–NET state gets about 8.5% and 92.3% improvement on construction and verification time costs with most hostile environment (AP = 80%) and largest policy scale (PS = 4000), which suggests CIADL is both efficient and scalable.
引用
收藏
页码:3473 / 3495
页数:22
相关论文
共 39 条
  • [1] CIADL: cloud insider attack detector and locator on multi-tenant network isolation: an OpenStack case study
    Zhan, Jing
    Fan, Xudong
    Han, Jin
    Gao, Yaqi
    Xia, Xiaoqing
    Zhang, Qian
    JOURNAL OF AMBIENT INTELLIGENCE AND HUMANIZED COMPUTING, 2020, 11 (09) : 3473 - 3495
  • [2] Multi-Tenant Network Acceleration Scheme for OpenStack
    Phan, Linh
    Liu, Kaikai
    2017 IEEE SMARTWORLD, UBIQUITOUS INTELLIGENCE & COMPUTING, ADVANCED & TRUSTED COMPUTED, SCALABLE COMPUTING & COMMUNICATIONS, CLOUD & BIG DATA COMPUTING, INTERNET OF PEOPLE AND SMART CITY INNOVATION (SMARTWORLD/SCALCOM/UIC/ATC/CBDCOM/IOP/SCI), 2017,
  • [3] Network Function Virtualization in the Multi-Tenant Cloud
    Yu, Ruozhou
    Xue, Guoliang
    Kilari, Vishnu Teja
    Zhang, Xiang
    IEEE NETWORK, 2015, 29 (03): : 42 - 47
  • [4] Performance of Multi-tenant Virtual Networks in OpenStack-based Cloud Infrastructures
    Callegati, Franco
    Cerroni, Walter
    Contoli, Chiara
    Santandrea, Giuliano
    2014 GLOBECOM WORKSHOPS (GC WKSHPS), 2014, : 81 - 85
  • [5] New Solution for Isolation of Multi-tenant in cloud computing
    Yang, Manzhi
    Zhou, Huixiang
    PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON MECHATRONICS, ROBOTICS AND AUTOMATION (ICMRA 2015), 2015, 15 : 334 - 337
  • [6] Multi-tenant Isolation of What? Building a Secure Tenant Isolation Architecture for Cloud Networks
    Medeiros, Bruno
    Simplicio, Marcos A., Jr.
    Andrade, Ewerton R.
    PROCEEDINGS OF THE 2018 ACM SYMPOSIUM ON CLOUD COMPUTING (SOCC '18), 2018, : 518 - 518
  • [7] Performance Study of Multi-tenant Cloud FPGAs
    Mbongue, Joel Mandebi
    Saha, Sujan Kumar
    Bobda, Christophe
    2021 IEEE INTERNATIONAL PARALLEL AND DISTRIBUTED PROCESSING SYMPOSIUM WORKSHOPS (IPDPSW), 2021, : 168 - 171
  • [8] Designing and Assessing Multi-tenant Isolation Strategies for Cloud Networks
    Medeiros, Bruno
    Simplicio, Marcos A., Jr.
    Andrade, Ewerton R.
    PROCEEDINGS OF THE 2019 22ND CONFERENCE ON INNOVATION IN CLOUDS, INTERNET AND NETWORKS AND WORKSHOPS (ICIN), 2019, : 214 - 221
  • [9] Simplifying Multi-layer and Multi-tenant Support in OpenStack: The SACHER Use Case
    Foschini, Luca
    Martuscelli, Giuseppe
    Montanari, Rebecca
    2019 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (ISCC), 2019, : 1183 - 1188
  • [10] A Security Architecture for Domain Isolation in Multi-Tenant Cloud FPGAs
    Mbongue, Joel Mandebi
    Saha, Sujan Kumar
    Bobda, Christophe
    2021 IEEE COMPUTER SOCIETY ANNUAL SYMPOSIUM ON VLSI (ISVLSI 2021), 2021, : 290 - 295