DESIGN AND IMPLEMENTATION OF OPENSTACK-BASED ADAPTIVE ANOMALY DETECTION MODEL

Hui Xiong,Zhihui Lü,Shiyong Zhang
DOI: https://doi.org/10.3969/j.issn.1000-386x.2015.09.069
2015-01-01
Abstract:Cloud computing is a computing mode which provides dynamical and scalable resources of virtualisation by means of services through Internet.The cloud services provided are based on existing normalised networks protocols and have specific formats and criteria. However current technologies and standard protocols exist security pitfalls,which open the door of invasion for illegal attackers.This paper comes up with CAPS (cloud adaptive PCA-SVM)model based on support vector machine (SVM)and primary component analysis (PCA). According to the data on OpenStack real cloud platform,the model uses PCA for data dimensionality reduction and adopts SVM classifier to submit the suspected anomalies to cloud security operator for verification.By constant iteration of the constructed classifier it is able to make adaptive detection on historical data.Experiment shows that the proposed CAPS has following strengths:(1 )Time consumption of adaptation process and average iteration is lower than standard SVM,and the efficiency is higher.(2)Achieving higher detection rate with lower false positive rate in real cloud environment compared with classic anomaly detection methods.
What problem does this paper attempt to address?