TY - GEN
T1 - Towards effective virtualization of intrusion detection systems
AU - Zhang, Nuyun
AU - Li, Hongda
AU - Hu, Hongxin
AU - Park, Younghee
N1 - Publisher Copyright:
© 2017 ACM.
PY - 2017/3/24
Y1 - 2017/3/24
N2 - Traditional Intrusion Detection Systems (IDSes) are generally implemented on vendor proprietary appliances or middleboxes, which usually lack a general programming interface, and their versatility and flexibility are also very poor. Emerging Network Function Virtualization (NFV) technology can virtualize IDSes and elastically scale them to deal with attack traffic variations. However, existing NFV solutions treat a virtualized IDS as a monolithic piece of software, which could lead to inflexibility and significant waste of resources. In this paper, we propose a novel approach to virtualize IDSes as microservices where the virtualized ID-Ses can be customized on demand, and the underlying microservices could be shared and scaled independently. We also conduct experiments, which demonstrate that virtualizing IDSes as microservices can gain greater flexibility and resource efficiency.
AB - Traditional Intrusion Detection Systems (IDSes) are generally implemented on vendor proprietary appliances or middleboxes, which usually lack a general programming interface, and their versatility and flexibility are also very poor. Emerging Network Function Virtualization (NFV) technology can virtualize IDSes and elastically scale them to deal with attack traffic variations. However, existing NFV solutions treat a virtualized IDS as a monolithic piece of software, which could lead to inflexibility and significant waste of resources. In this paper, we propose a novel approach to virtualize IDSes as microservices where the virtualized ID-Ses can be customized on demand, and the underlying microservices could be shared and scaled independently. We also conduct experiments, which demonstrate that virtualizing IDSes as microservices can gain greater flexibility and resource efficiency.
KW - Intrusion detection systems
KW - Microservices
KW - Network function virtualization
UR - https://www.scopus.com/pages/publications/85018255852
U2 - 10.1145/3040992.3041004
DO - 10.1145/3040992.3041004
M3 - Conference contribution
AN - SCOPUS:85018255852
T3 - SDN-NFVSec 2017 - Proceedings of the ACM International Workshop on Security in Software Defined Networks and Network Function Virtualization, co-located with CODASPY 2017
SP - 47
EP - 50
BT - SDN-NFVSec 2017 - Proceedings of the ACM International Workshop on Security in Software Defined Networks and Network Function Virtualization, co-located with CODASPY 2017
PB - Association for Computing Machinery
T2 - 2017 ACM International Workshop on Security in Software Defined Networks and Network Function Virtualization, SDN-NFVSec 2017, co-located with CODASPY 2017
Y2 - 24 March 2017 through 24 March 2017
ER -