CIADL: cloud insider attack detector and locator on multi-tenant network isolation: an OpenStack case study

被引:0
|
作者
Jing Zhan
Xudong Fan
Jin Han
Yaqi Gao
Xiaoqing Xia
Qian Zhang
机构
[1] Beijing University of Technology,College of Computer Science, Faculty of Information Technology
[2] Beijing University of Technology,Beijing Key Laboratory of Trusted Computing
[3] Beijing University of Technology,National Engineering Laboratory for Critical Technologies of Information Security Classified Protection
关键词
Cloud computing; Multi-tenant network isolation; Insider attack detection;
D O I
暂无
中图分类号
学科分类号
摘要
In cloud networks, edging network virtualization technology is widely adopted to protect tenants with isolated networks mainly from threats inside the cloud. However, since tenants completely rely on cloud service provider’s service interface to be aware of their current network policy, malicious admin alone or with concluded tenants is/are fully capable of acquiring any target tenant network data by attacking corresponding policies stored and enforced on the edging end hosts without tenants knowing. Therefore, this paper presents cloud insider attack detector and locator (CIADL) on multi-tenant network isolation for OpenStack. We propose an insider attack threat model with attack category. A layered state model based constructing and attack detection methods are also proposed, enabling efficient policy confliction detection between expected policy on central node and enforcing policy on end hosts. Along with a threat locating method with fine granularity of device policy rules for recovery purpose. We implements the proof of concept system of CIADL, and the experiments and analysis show our method can cover all attack types defined in threat model with low overheads, and scales well with network and policy size and attack number increase. Compared to existing work model with VM–VM state, CIADL state model with NET–NET state gets about 8.5% and 92.3% improvement on construction and verification time costs with most hostile environment (AP = 80%) and largest policy scale (PS = 4000), which suggests CIADL is both efficient and scalable.
引用
收藏
页码:3473 / 3495
页数:22
相关论文
共 39 条
  • [31] Towards Dynamic Request Updating With Elastic Scheduling for Multi-Tenant Cloud-Based Data Center Network
    Lu, Shuaibing
    Wu, Jie
    Shi, Jiamei
    Fang, Juan
    Zhang, Jiayue
    Liu, Haiming
    IEEE TRANSACTIONS ON NETWORK SCIENCE AND ENGINEERING, 2024, 11 (02): : 2223 - 2237
  • [32] Deep-Dup: An Adversarial Weight Duplication Attack Framework to Crush Deep Neural Network in Multi-Tenant FPGA
    Rakin, Adnan Siraj
    Luo, Yukui
    Xu, Xiaolin
    Fan, Deliang
    PROCEEDINGS OF THE 30TH USENIX SECURITY SYMPOSIUM, 2021, : 1919 - 1936
  • [33] M2cloud: Software Defined Multi-site Data Center Network Control Framework for Multi-tenant
    Liu, Zhongjin
    Li, Yong
    Su, Li
    Jin, Depeng
    Zeng, Lieguang
    ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2013, 43 (04) : 517 - 518
  • [34] Deep-Dup: An adversarial weight duplication attack framework to crush deep neural network in multi-tenant FPGA
    Rakin, Adnan Siraj
    Luo, Yukui
    Xu, Xiaolin
    Fan, Deliang
    Proceedings of the 30th USENIX Security Symposium, 2021, : 1919 - 1936
  • [35] Providing Multi-tenant Services with FPGAs: Case Study on a Key-Value Store
    Istvan, Zsolt
    Alonso, Gustavo
    Singla, Ankit
    2018 28TH INTERNATIONAL CONFERENCE ON FIELD PROGRAMMABLE LOGIC AND APPLICATIONS (FPL), 2018, : 119 - 124
  • [36] PARES: Packet Rewriting on SDN-Enabled Edge Switches for Network Virtualization in Multi-Tenant Cloud Data Centers
    Jeong, Kyuho
    Figueiredo, Renato
    Ichikawa, Kohei
    2017 IEEE 10TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING (CLOUD), 2017, : 9 - 17
  • [37] Evaluating Degrees of Tenant Isolation in Multitenancy Patterns: A Case Study of Cloud-hosted Version Control System (VCS)
    Ochei, Laud Charles
    Petrovski, Andrei
    Bass, Julian M.
    INTERNATIONAL CONFERENCE ON INFORMATION SOCIETY (I-SOCIETY 2015), 2015, : 59 - 66
  • [38] Fault and performance management in multi-cloud virtual network services using AI: A tutorial and a case study
    Gupta, Lav
    Salman, Tara
    Zolanvari, Maede
    Erbad, Aiman
    Jain, Raj
    COMPUTER NETWORKS, 2019, 165
  • [39] NON-ALCOHOLIC FATTY LIVER DISEASE AND CORONARY ARTERY CALCIFICATION SCORE BY MULTI-DETECTOR COMPUTED TOMOGRAPHY; CROSS-SECTIONAL CASE-CONTROL STUDY FROM HEALTHCARE CENTERS' NETWORK
    Kim, D.
    Park, E. H.
    Kim, W.
    Choi, S. -Y.
    Kim, Y. J.
    Yoon, J. -H.
    Cho, S. -H.
    Lee, H. -S.
    JOURNAL OF HEPATOLOGY, 2010, 52 : S145 - S146