Title :
A cloud computing based architecture for cyber security situation awareness
Author :
Wei Yu ; Guobin Xu ; Zhijiang Chen ; Moulema, Paul
Author_Institution :
Towson Univ., Towson, MD, USA
Abstract :
The exponential growth of cyber space has created opportunities for world-wide web-based businesses and information sharing, but also led to the proliferation of cyber attacks. To conduct the cyber security situation awareness, a large volume of data streams from monitored devices needs to be efficiently stored and processed in real time. In this paper, we propose a cloud computing based architecture for conducting cyber security situation awareness. Particularly, we leverage the cloud infrastructure with a cost-effective data storage and investigate efficient stream processing techniques to reduce operational delays. To effectively detect threats, we present a parallel cloud based threat detection that integrates both signature-based detection and anomaly-based detection. To capture the insightful characteristics of attacks, we discuss the attack scene analysis based on spatiotemporal correlation and visualization schemes to analyze, trace, and visualize abnormal behaviors. Lastly, we present the testbed setup and the implementation workflow to validate the effectiveness of our proposed system.
Keywords :
Web sites; cloud computing; security of data; World-Wide Web-based businesses; abnormal behavior analysis; abnormal behavior tracing; abnormal behavior visualization; anomaly-based detection; attack characteristics; attack scene analysis; cloud computing based architecture; cloud infrastructure; cost-effective data storage; cyber attack proliferation; cyber security situation awareness; information sharing; parallel cloud based threat detection; real time data stream processing; real time data stream storage; signature-based detection; spatiotemporal correlation and visualization schemes; stream processing techniques; Cloud computing; Computer architecture; Computer security; Data processing; Monitoring; Servers; Cloud Computing; Cyber Security; MapReduce; Situation Awareness;
Conference_Titel :
Communications and Network Security (CNS), 2013 IEEE Conference on
Conference_Location :
National Harbor, MD
DOI :
10.1109/CNS.2013.6682765