Identification of Program Signatures from Cloud Computing System Telemetry Data
Malicious cloud computing activity can take many forms, including running unauthorized programs in a virtual environment. Detection of these malicious activities while preserving the privacy of the user is an important research challenge. Prior work has shown the potential viability of using cloud service billing metrics as a mechanism for proxy identification of malicious programs. Previously this novel detection method has been evaluated in a synthetic and isolated computational environment. In this paper we demonstrate the ability of billing metrics to identify programs, in an active cloud computing environment, including multiple virtual machines running on the same hypervisor. The open source cloud computing platform OpenStack, is used for private cloud management at Pacific Northwest National Laboratory. OpenStack provides a billing tool (Ceilometer) to collect system telemetry measurements. We identify four different programs running on four virtual machines under the same cloud user account. Programs were identified with up to 95% accuracy. This accuracy is dependent on the distinctiveness of telemetry measurements for the specific programs we tested. Future work will examine the scalability of this approach for a larger selection of programs to better understand the uniqueness needed to identify a program. Additionally, future work should address the separation of signatures when multiple programs are running on the same virtual machine.
- Research Organization:
- Pacific Northwest National Laboratory (PNNL), Richland, WA (US)
- Sponsoring Organization:
- USDOE
- DOE Contract Number:
- AC05-76RL01830
- OSTI ID:
- 1440703
- Report Number(s):
- PNNL-SA-121720
- Country of Publication:
- United States
- Language:
- English
Similar Records
Automated platform to assess commercial off the shelf (COTS) software assurance
Virtual Cluster Management with Xen
Cloud forensics and incident response platform
Patent
·
Tue Aug 08 00:00:00 EDT 2023
·
OSTI ID:2222084
Virtual Cluster Management with Xen
Conference
·
Mon Dec 31 23:00:00 EST 2007
·
OSTI ID:931221
Cloud forensics and incident response platform
Patent
·
Tue Sep 07 00:00:00 EDT 2021
·
OSTI ID:1840421