Visible to the public Towards Effective Virtualization of Intrusion Detection Systems

TitleTowards Effective Virtualization of Intrusion Detection Systems
Publication TypeConference Paper
Year of Publication2017
AuthorsZhang, Nuyun, Li, Hongda, Hu, Hongxin, Park, Younghee
Conference NameProceedings of the ACM International Workshop on Security in Software Defined Networks & Network Function Virtualization
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-4908-6
Keywordscomposability, Human Behavior, Intrusion Detection Systems, Metrics, microservices, network function virtualization, privacy, pubcrawl, resilience, Resiliency, virtualization privacy
Abstract

Traditional Intrusion Detection Systems (IDSes) are generally implemented on vendor proprietary appliances or middleboxes, which usually lack a general programming interface, and their versatility and flexibility are also very poor. Emerging Network Function Virtualization (NFV) technology can virtualize IDSes and elastically scale them to deal with attack traffic variations. However, existing NFV solutions treat a virtualized IDS as a monolithic piece of software, which could lead to inflexibility and significant waste of resources. In this paper, we propose a novel approach to virtualize IDSes as microservices where the virtualized IDSes can be customized on demand, and the underlying microservices could be shared and scaled independently. We also conduct experiments, which demonstrate that virtualizing IDSes as microservices can gain greater flexibility and resource efficiency.

URLhttp://doi.acm.org/10.1145/3040992.3041004
DOI10.1145/3040992.3041004
Citation Keyzhang_towards_2017