- Research Article
- 10.25972/opus-22421
Attack-aware Security Function Management
- May 03, 2021
- Online Publication Service of Würzburg University (Würzburg University)
- Lukas Iffländer
Attack-aware Security Function Management
Cloud computing has gained lots of popularity in recent times as it fulfil the dream model “Computing as Utility”, it emerged in the market as huge technological growth in the form of on-demand service for business customers such as software, platform and infrastructure needs and requirements. The model as “pay as you go” help companies in IT growth without much planning as everything is on pay-based model. Despite all the factors and scalable infrastructure of cloud network, there are less concern and cautions about the security issues pertain to cloud computing. Cloud computing can be taken as most significant shift in IT paradigm of recent times but still there are great deal of work is required in the area of security to handle the attack spreading and polluting the cloud infrastructure. In this paper, the security issues by gathering the attak data in the cloud network by desiging, implementing the honeypot as cyber attack mitigation solution is presented. The concept is to design a cloud setup and assess the security issues by putting the honeypot in the cloud enviornment. This artical include the honeypot implementation along with Intrusion detection system using a Ubuntu based OwnCloud utility. The real statistical data collected, analysed and categorized in a automatic way through novel signatures based engines.
Attack-aware Security Function Management
Attack-aware Security Function Management
Incident Detection over Unified Threat Management Platform on a Cloud Network
Artificial Intelligence (AI) techniques provide many intelligent methods for security solutions in various domains such as finance, networking, cloud computing, health records and individual's identity. AI achieves security mechanisms like antivirus, firewalls, intrusion detection system (IDS) and cryptography by using machine learning methods and data analysis techniques. As the modern AI techniques help improving security systems, criminal activities are also becoming updated simultaneously. Machine learning methods along with data analysis tools have become popular to prevent security systems from threats and hacking activities. This work contributes to secure cloud networks and help them prevent malicious attacks. In this paper, Bidirectional long short-term memory (BLSTM) is used to detect incidents over unified threat management (UTM) platform operated on cloud network. Results are compared with K-nearest neighbor which is a baseline technique. Time series input samples recorded over UTM platform are used for training and testing purposes. We obtain accuracy score of 98.47% with 0.0186 mean squared error (MSE) using KNN while BLSTM provides 98.6% accuracy score with 0.002 loss, which is better than the KNN.
Read moreCloud Networks as Platform-based Ecosystems : Detecting Management Implications for Actors in Cloud Networks
Platform-based ecosystems are omnipresent in today’s world. This doctoral thesis focuses on cloud computing, which is an emerging platform-based ecosystem that companies adopt in their IT strategy quickly. Actors in cloud computing often create value by adding functionality to services already existing in the ecosystem. This development is likely to transform cloud computing toward complex, globally distributed networks, consisting of many different actors and connections. In the doctoral thesis I define those structures as cloud networks. For general platform-based ecosystems, Tiwana et al. (2010) and de Reuver et al. (2018) each set up a research agenda for platform-based ecosystems. I contribute to four proposed research items: (1) Tiwana et al. (2010) demand research on how platform architecture influences the dynamics in ecosystems and modules. (2) de Reuver et al. (2018) emphasize research on the question regarding how actors strategize, i.e., think strategically, about a situation or business in platform environments, as interconnected thinking is particularly important for decision makers. (3) de Reuver et al. (2018) demand research on how platform providers can jointly shape platforms with other stakeholders of the platform. (4) Tiwana et al. (2010) emphasize research on how the fit between platform architecture and platform governance influences the dynamics of ecosystems and modules. The doctoral thesis consists of five papers that directly contribute to these research items. By providing a taxonomy of actors, a taxonomy of risks, as well as a reference model that enables the instantiation interactions between actors in cloud networks, it provides a tool that enables the illustration of dynamics in cloud networks. Next, it illustrates strategies for companies in platform-based ecosystems and provides guidance for ITgovernance with respect to the specific characteristics of cloud networks. Also, it analyzes how customers can utilize cloud spot prices to monetarize their temporal flexibility. To illustrate the shaping of platforms, the dissertation describes preliminary design principles for a power flexibility platform that many companies develop jointly in a publicly funded research project. By analyzing the utilization of cloud spot prices and by describing preliminary design principles for the power flexibility platform, the thesis further guides actors on how to utilize digital options in platform environments, and it provides decision support for specific scenarios which could transfer knowledge to the general context of platform-based ecosystems. Finally, the doctoral thesis analyzes how platform governance influences the dynamics in platform-based ecosystems and provides guidance for IT-governance with respect to the specific characteristics of cloud networks.%%%%Plattformbasierte Okosysteme sind in der heutigen Welt allgegenwartig. Diese Dissertation konzentriert sich auf Cloud Computing, ein aufstrebendes, plattformbasiertes Okosystem, das Unternehmen schnell in ihren IT-Strategien…
Read moreBlockchain and federated learning-based intrusion detection approaches for edge-enabled industrial IoT networks: a survey
Blockchain and federated learning-based intrusion detection approaches for edge-enabled industrial IoT networks: a survey
Read moreSurvey on Data Security Issues in Cloud Computing
Cloud Computing is a way to deal with fabricate the breaking point or incorporate capacities effectively without placing assets into new system, planning new staff, or approving new programming. They have various potential purposes of intrigue and various attempt applications and data are moving to open or half and half cloud. However, regarding some business-fundamental applications, the affiliations, especially considerable attempts, still wouldn't move them to cloud. The market gauge the Cloud Computing shared is as yet far behind the one expected. From the clients' perspective, Cloud Computing security concerns, especially data security and security confirmation issues, remain the basic inhibitor for gathering of Cloud Computing organizations. In this paper, we present a diagram on data security and security protection issues related with Cloud Computing over all periods of data life cycle. Firstly,, we moreover focus a related works and after that we show unpretentious components of Cloud Computing security issues, and a short time later data security and insurance affirmation issues, and a while later we display some present courses of action in cloud. Finally, we look at future work about data security and security affirmation issues in cloud. Keywords: cloud computing; security deployment; privacy protection infrastructure.
Read moreIDPS based framework for security in green cloud computing and comprehensive review on existing frameworks and security issues
IT sector is growing day by day, its data and energy costs are also increasing, which needs to access the high-end computing capabilities. To fulfill these requirements, there is a need to shift from traditional computing practices to new computing practices that give access to a broader network, unlimited resources, and enables self-service on demand at a reasonable cost using pay per use method. All these requirements can be fulfilled with cloud computing. Cloud Computing has a number of advantages as well as disadvantages. Security is a major threat to the cloud computing because the data placed on cloud servers is always vulnerable as there are lots of attackers on the internet who tries to compromise the security of the cloud. To overcome this issue, we use security appliances in the form of physical machines or by virtualization. A significant amount of power is consumed by security appliances which not only leads to the high energy costs but also a major threat to the environment as carbon-dioxide is released. So there is a need to find optimal solutions for providing security in cloud computing environment in an efficient manner. In this paper, a comprehensive survey on existing cloud security frameworks has been done. Based upon the limitations on existing frameworks a new framework has been proposed to provide security in virtual networks that is based on Intrusion Detection and Prevention System (IDPS) and its prototype implementation has also been done.
Read moreDeep Learning Based Intrusion Detection System: Software Defined Network
Software-defined Networking (SDN) is the key catalyst in the next-generation network. Cloud computing has shown rapid growth due to the development of SDN. Due to the growth in security difficulties and threats, SDN networks will have new security issues to overcome, and a new layer of security procedures, such as intrusion detection systems (IDS), is required. Nowadays, web services are flexible, economical, and user-friendly. Although this may be true, they still seem to be more susceptible to security issues than legacy systems. Therefore, SDN architecture also incorporates several machine learning methods to find classify malicious attacks and legitimate traffic. We include a rigorous study of the current strategies for malicious traffic identification and we define the classical machine learning method's shortcomings, and a deep learning technique is also being investigated to reach higher levels of efficiency and accuracy. This article explores SDN security and IDS about security concerns. A dataset of IDS, publicly accessible, KDD-CUP99, and NSL-KDD Dataset are used to determine the possible behaviour of security flaws.
Read moreInternet of Things Security: We're Walking on Eggshells!
Since the Internet of Things (IoT) will be entwined with everything we use in our daily life, the consequence of security flaws escalates. Smart objects will govern most of the home appliances and car engines yielding potential disaster scenarios. In this context, successful attacks could lead to chaos and scary scenarios (www.darkreading.com). Unprotected personal information may expose sensitive and embarrassing data to the public and attacks may threaten not only our computers and smart devices, but our intimacy and perhaps our lives too. Because persons and objects will be bonded with each other, user consent becomes critical. Therefore, thing, object, and user Identity will be the focus of future IoT security solutions, yielding a Trust, Security, and Privacy (TSP) paradigm, which may constitute the Achilles' heel of IoT. While security issues are quite straightforward, mainly from background knowledge, privacy issues are far more complex. Privacy constitutes a rather challenging task, even for the m...
Read moreReview of CIDS and Techniques of Detection of Malicious Insiders in Cloud-Based Environment
Cloud computing has gained an extreme importance nowadays. Every organization is getting attracted toward the Cloud computing due to its attractive features like cost saving, adaptability, etc. Although it offers the attractive features but still Cloud threats need great consideration. The insider threat is critically challenging in the Cloud-based environments. In order to mitigate from insider attacks in Clouds, the use of Intrusion detection system (IDS) is quite challenging. Every type of IDS has different methods of attack detection. So, single IDS cannot guarantee the protection from all types of attacks. Thus, in this paper, we have studied the various types of IDS and their features which made them either suitable or unsuitable for cloud computing. Also on the basis of review, required features for the Cloud-based IDS are identified.
Read moreInternet of things intrusion detection model and algorithm based on cloud computing and multi-feature extraction extreme learning machine
Internet of things intrusion detection model and algorithm based on cloud computing and multi-feature extraction extreme learning machine
Read moreAn assessment of audio file from library system (social networks) using cloud computing
Accessing data from social networks using cloud computing has been adopted by many IT enthusiasts. It allows easy access to data and easy sending of data for communication purposes. For many social network users, cloud computing can simplify processes and save time and money. This article defines cloud computing and shows how one can quickly, safely and easily access data. It also discusses how cloud computing solutions could be beneficial to libraries in these basic areas: technology and acquisition.Today’s more libraries and social networks are joining the cloud. But despite the numerous social networks and data acquisition sites demand for data are still escalating—as they always will. To be able to access data conveniently today’s data competitiveness users of search engines must carefully scrutinize various libraries as well as social media to ensure that they match key data and communication needs and deliver intended results in the most efficient and cost-effective way. To meet these challenges, IT organizations are increasingly moving away from a device-centric view of IT, to a view that is application-, information- and people-centric. Cloud computing aligns with this new world view. Cloud computing technology is enabling IT to do more with the infrastructure that already exists, as well as adding new ways to expand capacity quickly and economically by using external cloud computing resources. This technology is enabling IT managers to treat infrastructure as a common substrate on which they can provision services to users faster in a much more flexible and cost-effective way –without having to re-design or add to the underlying infrastructure. Given the benefits of cloud computing, its broad appeal is not surprising. However, this new approach does raise some concerns. Chief among them is securing data in the cloud. This white paper will briefly review the basic fundamentals of cloud computing and describe how virtualization are enabling enterprises to move toward a flexible, federated computing model with a cohesive mix of private external and internal cloud environments. It then discusses the security implications of cloud computing and provides insights into addressing them, and offers a view of security best practices to adopt when considering cloud services.Cloud computing has become an increasingly popular means of delivering valuable, IT-enabled business services. Adopting cloud technology can be an affordable way to get access to a dynamically scalable, virtualized computing environment. Optimal IT hardware, software, expertise and infrastructure management resources that may not otherwise be available from a cost perspective can be rapidly deployed and easily scaled. Processes, applications and services can be available on demand, regard-less of the user location or device. The cloud provider is responsible for the environment, so organizations can make use of resources for short periods of time without having to maintain the environment when it is not being used. While cloud computing models are attractive because of their flexibility and cost effectiveness, certain challenges must be addressed in order to provide a viable option to traditional data services. First and foremost is the issue of security. The externalized aspect of outsourcing can make it harder to maintain data integrity and privacy, support data and service availability, demonstrate compliance, and secure highly available access to applications and information. In short, cloud computing can present an added level of risk. Organizations must therefore establish trust relationships with their cloud computing providers and understand risk in terms of how these providers implement, deploy, and manage security on their behalf. Whether delivered as part of the service or as specific components added in, your cloud provider should address the fundamentals of security and risk management through a comprehensive approach.
Read moreID-SOMGA: A Self Organising Migrating Genetic Algorithm-Based Solution for Intrusion Detection
The study examined the detection of attacks against computer networks, which is becoming a harder problem to solve in the field of Network security. A problem with current intrusion detection systems is that they have many false positive and false negative events. Most of the existing Intrusion detection systems implemented depend on rule-based expert systems where new attacks are not detectable. In this study, optimization algorithms were added to intrusion detection system to make them more efficient. Self Organizing Migrating Genetic Algorithm (SOMGA) was integrated into intrusion detection system to obtain a more efficient intrusion detection system called ID-SOMGA. This study provides an equally efficient method to implement an intrusion detection system that returns very low false positives. Due to the complexities involved in security issues, and the implementation of the work, selected values of the network log was used to implement the system in order to reduce some of these complexities. The Self Organizing Migrating Genetic Algorithm – Intrusion Detection System was tested and values of the result were compared with that of an IDS with Genetic Algorithm Intrusion Detection System. In terms of detection rates, ID-SOMGA was found to be slower than an IDS with GA, the false positives in ID-SOMGA was lower than what obtains with genetic algorithm. Both schemes were able to identify new patterns almost in the same way. The ID-SOMGA system that was developed improved the security of systems in networked settings allowing for confidentiality, integrity and availability of system resources.
Read moreA New Approach Based on a Multi–Agent System for IDS in Cloud Computing
Cloud computing is a recent innovation in the IT industry that is expanding quickly. Furthermore, this technology is widely used to provide computation, data storage, and other resources remotely through the web on a pay-per-usage basis. It is now the favored option for any IT firm since it increases its capacity to satisfy the computing requirements of its everyday operations through scalability, mobility, and flexibility at a low price. But there are two key problems with cloud computing. The biggest issue is storage-related, and Google has addressed it by adding a new layer to the cloud dubbed “Big data as a service (BDaaS).” The second problem is security and privacy. The Intrusion Detection System (IDS) has become the most widely utilized component of computer systems, security, and compliance processes, safeguarding network-accessible Cloud resources and services from various threats and assaults. This study examines IDS approaches in Cloud Computing and big data sets. To identify anomalous data in BDaaS, we also suggested a sensible intrusion detection system (SIDS) based on the autonomic system. The agent contributes the most to introducing more proprieties, particularly the autonomy element.
Read moreThe Employment of Context-Awareness Intrusion Detection Systems using AI: Strengthen Cybersecurity in Smart Cities
With the development of Internet of Things communities, the complexity and scale of cyber security threats multiply swiftly in these intelligent cities and their connected digital infrastructure. As hybrid computing and cyber environment continue to develop, NGID systems become increasingly fragile because of their lack of adaptability and the ability to understand local context to accurately detect the cyber-attacks in dynamic cyber environment like cloud computing. The current work investigates the design and deployment of context-awareness intrusion detection systems (IDS) based on advanced artificial intelligence (AI) approaches to improve a security framework in smart city. Utilizing the real time environmental, network and user behavior data, the IDS models introduced here can optimize detection parameters as dynamic, to improve the anomaly recognition, false positives’ reduction and response time. The research is aiming at combining context information from multiple and diverse internet of things devices, and sensors, and communication networks, so as to enable AI algorithms to build a complete situational awareness model. Such context-aware processing enables the IDS to draw the borderline between normal operation and attacks more accurately. Machine learning techniques, like deep learning and reinforcement learning, can be used to continuously enhance the power of detection over adaptive leaning and build robustness against zero-day attacks and adaptive threats. In addition, the software architecture highlights fog computing for real-time threat detection and transmission from edge to network and it emphasizes a decentralized processing system at the edge of the network while maintaining data privacy. Experimental results, analyzed on several simulated smart city networks, clearly show that the context-aware AI-based IDS performs considerably better than traditional IDSs on detecting a variety of cyber threats like DDoS attacks, data breaches, and unauthorized access attempts. The results demonstrate the system's strength, scalability, and efficiency, which points a promising trend for securing the digital backbone of the future smart cities. This work paves the way for smarter, secure urban ecosystems by leveraging AI and context-awareness in the domain of cybersecurity.
Read moreA Survey on Various Security Issues and Challenges to Secure Cloud Computing
A Survey on Various Security Issues and Challenges to Secure Cloud Computing