Hybrid Intrusion Detection System Using Machine Learning Techniques in Cloud Computing Environments

Intrusion detection is one essential tool towards building secure and trustworthy Cloud computing environment, given the ubiquitous presence of cyber attacks that proliferate rapidly and morph dynamically. In our current working paradigm of resource, platform and service consolidations, Cloud Computing provides a significant improvement in the cost metrics via dynamic provisioning of IT services. Since almost all cloud computing networks lean on providing their services through Internet, they are prone to experience variety of security issues. Therefore, in cloud environments, it is necessary to deploy an Intrusion Detection System (IDS) to detect new and unknown attacks in addition to signature based known attacks, with high accuracy. In our deliberation we assume that a system or a network “anomalous” event is synonymous to an “intrusion” event when there is a significant departure in one or more underlying system or network activities. There are couple of recently proposed ideas that aim to develop a hybrid detection mechanism, combining advantages of signature-based detection schemes with the ability to detect unknown attacks based on anomalies. In this work, we propose a network based anomaly detection system at the Cloud Hypervisor level that utilizes a hybrid algorithm: a combination of K-means clustering algorithm and SVM classification algorithm, to improve the accuracy of the anomaly detection system. Dataset from UNSW-NB15 study is used to evaluate the proposed approach and results are compared with previous studies. The accuracy for our proposed K-means clustering model is slightly higher than others. However, the accuracy we obtained from the SVM model is still low for supervised techniques.

[1]  Samuel Kounev,et al.  Evaluating Computer Intrusion Detection Systems , 2015, ACM Comput. Surv..

[2]  Ali Hushyar Network traffic clustering and geographic visualization , 2009 .

[3]  David Pierrot,et al.  Hybrid Intrusion Detection in Information Systems , 2016, 2016 International Conference on Information Science and Security (ICISS).

[4]  G.P.Saradhi Varma,et al.  CLASSIFICATION OF NETWORK VIOLATION DETECTION USING MACHINE LEARNING , 2018 .

[5]  Shadi Aljawarneh,et al.  Anomaly-based intrusion detection system through feature selection analysis and building hybrid efficient model , 2017, J. Comput. Sci..

[6]  Gregory Ditzler,et al.  Learning in Nonstationary Environments: A Survey , 2015, IEEE Computational Intelligence Magazine.

[7]  Nour Moustafa,et al.  UNSW-NB15: a comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set) , 2015, 2015 Military Communications and Information Systems Conference (MilCIS).

[8]  VARUN CHANDOLA,et al.  Anomaly detection: A survey , 2009, CSUR.

[9]  Jinoh Kim,et al.  Unsupervised Labeling for Supervised Anomaly Detection in Enterprise and Cloud Networks , 2017, 2017 IEEE 4th International Conference on Cyber Security and Cloud Computing (CSCloud).

[10]  Belaid Moa,et al.  Hypervisor-based cloud intrusion detection through online multivariate statistical change tracking , 2020, Comput. Secur..