Title :
A Finite Context Intrusion Prediction Model for Cloud Systems with a Probabilistic Suffix Tree
Author :
Kholidy, Hisham A. ; Yousof, Ahmed M. ; Erradi, Abdelkarim ; Abdelwahed, Sherif ; Ali, Hisham Arafat
Author_Institution :
Comput. Sci. & Eng., Qatar Univ., Doha, Qatar
Abstract :
The success of the cloud computing paradigm depends on how effectively the cloud infrastructures will be able to instantiate and dynamically maintain computing platforms that meet Quality of Service (QoS) requirements. Most of the current security technologies do not provide early warnings about future ongoing attacks. This paper introduces new techniques in prediction model that is built based on Variable Order Markov Model and Probabilistic Suffix Tree. The proposed model uses a risk assessment model to evaluate the overall risk in the cloud system. According to our experiments on DARPA 2000 dataset, the prediction model has successfully signaled early warning alerts 58.983 minutes before the launching of the LLDDoS1.0 attack and 43.93 minutes before the launching of the LLDDoS2.0. This gives the system administrator or an autonomic system ample time to take corrective action.
Keywords :
Markov processes; cloud computing; probability; quality of service; risk management; security of data; software fault tolerance; trees (mathematics); DARPA 2000 dataset; LLDDoS1.0 attack; LLDDoS2.0; QoS requirements; autonomic system; cloud computing paradigm; cloud infrastructures; cloud systems; finite context intrusion prediction model; overall risk evaluation; probabilistic suffix tree; quality-of-service requirements; risk assessment model; variable order Markov model; Computational modeling; Context modeling; Hidden Markov models; Markov processes; Predictive models; Probabilistic logic; Training; cloud computing; security; privacy; intrusion detection systems; intrusion prediction; variable order markov model; probabilistic suffix tree;
Conference_Titel :
Modelling Symposium (EMS), 2014 European
Print_ISBN :
978-1-4799-7411-5
DOI :
10.1109/EMS.2014.90