VNIDS: A virtual machine-based network intrusion detection system

Feng Zhao,Weiping Yang,Hai Jin,Song Wu
DOI: https://doi.org/10.1109/IWASID.2008.4688384
2008-01-01
Abstract:In recent years, virtualization technology has been widely applied to traditional computing environment. As it provides strong flexibility, the security in face of attacks to network services becomes a significant challenge. In this paper, we propose a novel architecture to detect intrusion in virtual computing environment and implement a prototype, named VNIDS. In this system, a particular VM is designed to provide intrusion detection services for other VMs. Especially, the rule list can be constructed dynamically for each virtual machine respectively. Moreover, the data detector, which is the core component of VNIDS and isolated from the target virtual machines, has a good view about the state of the target virtual machines. Additionally, in order to transmit the detection information generated by the VNIDS to the target VM, a cross-domain communication module is introduced. Finally, we use a series of intrusion tools to validate VNIDS and the experiment results indicate that it can detect attacks effectively.
What problem does this paper attempt to address?