• DocumentCode
    561138
  • Title

    DCDIDP: A distributed, collaborative, and data-driven intrusion detection and prevention framework for cloud computing environments

  • Author

    Zargar, Saman Taghavi ; Takabi, Hassan ; Joshi, James B D

  • Author_Institution
    Sch. of Inf. Sci., Univ. of Pittsburgh, Pittsburgh, PA, USA
  • fYear
    2011
  • fDate
    15-18 Oct. 2011
  • Firstpage
    332
  • Lastpage
    341
  • Abstract
    With the growing popularity of cloud computing, the exploitation of possible vulnerabilities grows at the same pace; the distributed nature of the cloud makes it an attractive target for potential intruders. Despite security issues delaying its adoption, cloud computing has already become an unstoppable force; thus, security mechanisms to ensure its secure adoption are an immediate need. Here, we focus on intrusion detection and prevention systems (IDPSs) to defend against the intruders. In this paper, we propose a Distributed, Collaborative, and Data-driven Intrusion Detection and Prevention system (DCDIDP). Its goal is to make use of the resources in the cloud and provide a holistic IDPS for all cloud service providers which collaborate with other peers in a distributed manner at different architectural levels to respond to attacks. We present the DCDIDP framework, whose infrastructure level is composed of three logical layers: network, host, and global as well as platform and software levels. Then, we review its components and discuss some existing approaches to be used for the modules in our proposed framework. Furthermore, we discuss developing a comprehensive trust management framework to support the establishment and evolution of trust among different cloud service providers.
  • Keywords
    cloud computing; security of data; architectural levels; cloud computing environments; cloud service providers; distributed collaborative and data-driven intrusion detection; global layer; host layer; infrastructure level; intrusion detection and prevention systems; logical layers; network layer; platform levels; security mechanisms; software levels; Computational modeling; Indium tin oxide; Load modeling; Virtual machine monitors; Cloud computing; collaborative IDPS; distributed IDPS; intrusion detection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Collaborative Computing: Networking, Applications and Worksharing (CollaborateCom), 2011 7th International Conference on
  • Conference_Location
    Orlando, FL
  • Print_ISBN
    978-1-4673-0683-6
  • Electronic_ISBN
    978-1-936968-32-9
  • Type

    conf

  • Filename
    6144819