{"title":"用于私有云的集中式HIDS框架","authors":"Zhijian Wang, Yanqin Zhu","doi":"10.1109/SNPD.2017.8022709","DOIUrl":null,"url":null,"abstract":"Cloud computing is more convenient and efficient than traditional on-premise computing for users, as it provides large scale resources, software, and information to each customer. However, cloud computing systems can be easily threatened by various cyber attacks. Therefore, an Intrusion Detection System (IDS) is very necessary for cloud computing system. There is a serious problem which traditional host-based IDS for cloud computing consumes a large amount of system resources. In this paper, we propose a centralized host-based IDS framework to reduce the use of the resources. Using logstash tool to collect the system logs from each virtual machine, and storing them into elasticsearch cluster centrally. After that, we analyze all these logs in the detection center and send the results to each virtual machine. We have validated our framework in the openstack platform. The results show a good performance in reducing the CPU and memory usage.","PeriodicalId":186094,"journal":{"name":"2017 18th IEEE/ACIS International Conference on Software Engineering, Artificial Intelligence, Networking and Parallel/Distributed Computing (SNPD)","volume":"38 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2017-06-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"22","resultStr":"{\"title\":\"A centralized HIDS framework for private cloud\",\"authors\":\"Zhijian Wang, Yanqin Zhu\",\"doi\":\"10.1109/SNPD.2017.8022709\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Cloud computing is more convenient and efficient than traditional on-premise computing for users, as it provides large scale resources, software, and information to each customer. However, cloud computing systems can be easily threatened by various cyber attacks. Therefore, an Intrusion Detection System (IDS) is very necessary for cloud computing system. There is a serious problem which traditional host-based IDS for cloud computing consumes a large amount of system resources. In this paper, we propose a centralized host-based IDS framework to reduce the use of the resources. Using logstash tool to collect the system logs from each virtual machine, and storing them into elasticsearch cluster centrally. After that, we analyze all these logs in the detection center and send the results to each virtual machine. We have validated our framework in the openstack platform. The results show a good performance in reducing the CPU and memory usage.\",\"PeriodicalId\":186094,\"journal\":{\"name\":\"2017 18th IEEE/ACIS International Conference on Software Engineering, Artificial Intelligence, Networking and Parallel/Distributed Computing (SNPD)\",\"volume\":\"38 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2017-06-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"22\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2017 18th IEEE/ACIS International Conference on Software Engineering, Artificial Intelligence, Networking and Parallel/Distributed Computing (SNPD)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/SNPD.2017.8022709\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2017 18th IEEE/ACIS International Conference on Software Engineering, Artificial Intelligence, Networking and Parallel/Distributed Computing (SNPD)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SNPD.2017.8022709","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Cloud computing is more convenient and efficient than traditional on-premise computing for users, as it provides large scale resources, software, and information to each customer. However, cloud computing systems can be easily threatened by various cyber attacks. Therefore, an Intrusion Detection System (IDS) is very necessary for cloud computing system. There is a serious problem which traditional host-based IDS for cloud computing consumes a large amount of system resources. In this paper, we propose a centralized host-based IDS framework to reduce the use of the resources. Using logstash tool to collect the system logs from each virtual machine, and storing them into elasticsearch cluster centrally. After that, we analyze all these logs in the detection center and send the results to each virtual machine. We have validated our framework in the openstack platform. The results show a good performance in reducing the CPU and memory usage.