Skip to main navigation Skip to search Skip to main content

Scalable network intrusion detection and countermeasure selection in virtual network systems

  • Jin B. Hong*
  • , Chun Jen Chung
  • , Dijiang Huang
  • , Dong Seong Kim
  • *Corresponding author for this work
  • University of Canterbury
  • Arizona State University

Research output: Chapter in Book or Report/Conference proceedingConference Proceedingpeer-review

2 Citations (Scopus)

Abstract

Security of virtual network systems, such as Cloud computing systems, is important to users and administrators. One of the major issues with Cloud security is detecting intrusions to provide time-efficient and cost-effective countermeasures. Cyber-attacks involve series of exploiting vulnerabilities in virtual machines, which could potentially cause a loss of credentials and disrupt services (e.g., privilege escalation attacks). Intrusion detection and countermeasure selection mechanisms are proposed to address the aforementioned issues, but existing solutions with traditional security models (e.g., Attack Graphs (AG)) do not scale well with a large number of hosts in the Cloud systems. Consequently, the model cannot provide a security solution in practical time. To address this problem, we incorporate a scalable security model named Hierarchical Attack Representation Model (HARM) in place of the AG to improve the scalability. By doing so, we can provide a security solution within a reasonable timeframe to mitigate cyber attacks. Further, we show the equivalent security analysis using the HARM and the AG, as well as to demonstrate how to transform the existing AG to the HARM.

Original languageEnglish
Title of host publicationAlgorithms and Architectures for Parallel Processing - ICA3PP International Workshops and Symposiums, Proceedings
EditorsGregorio Martinez Perez, Albert Zomaya, Kenli Li, Guojun Wang
PublisherSpringer Verlag
Pages582-592
Number of pages11
ISBN (Print)9783319271606
DOIs
Publication statusPublished - 2015
Event15th International Conference on Algorithms and Architectures for Parallel Processing, ICA3PP 2015 - Zhangjiajie, China
Duration: 18 Nov 201520 Nov 2015

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume9532
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference15th International Conference on Algorithms and Architectures for Parallel Processing, ICA3PP 2015
Country/TerritoryChina
CityZhangjiajie
Period18/11/1520/11/15

Keywords

  • Attack graphs
  • Countermeasure selection
  • Intrusion detection
  • Network security
  • Scalability

Cite this