Visible to the public New security architecture using hybrid IDS for virtual private clouds

TitleNew security architecture using hybrid IDS for virtual private clouds
Publication TypeConference Paper
Year of Publication2019
AuthorsELMAARADI, Ayoub, LYHYAOUI, Abdelouahid, CHAIRI, IKRAM
Conference Name2019 Third International Conference on Intelligent Computing in Data Sciences (ICDS)
PublisherIEEE
ISBN Number978-1-7281-0003-6
Keywordsanomalies detection, artificial neural network, cloud computing, computer network security, cyber-attacks, data privacy, detection engine, digital revolution, digital transformation, host-based intrusion detection system, hybrid IDS, hybrid Intrusion Detection System, IDS, IDS based ANN, intrusion detection system, learning (artificial intelligence), machine learning, Malicious Traffic, Network security, network-based IDS, network-based intrusion detection system, neural nets, privacy vulnerability, private cloud environments, pubcrawl, security architecture, telecommunication traffic, virtual machine, virtual machine security, virtual machines, virtual private cloud, virtual private clouds
Abstract

We recently see a real digital revolution where all companies prefer to use cloud computing because of its capability to offer a simplest way to deploy the needed services. However, this digital transformation has generated different security challenges as the privacy vulnerability against cyber-attacks. In this work we will present a new architecture of a hybrid Intrusion detection System, IDS for virtual private clouds, this architecture combines both network-based and host-based intrusion detection system to overcome the limitation of each other, in case the intruder bypassed the Network-based IDS and gained access to a host, in intend to enhance security in private cloud environments. We propose to use a non-traditional mechanism in the conception of the IDS (the detection engine). Machine learning, ML algorithms will can be used to build the IDS in both parts, to detect malicious traffic in the Network-based part as an additional layer for network security, and also detect anomalies in the Host-based part to provide more privacy and confidentiality in the virtual machine. It's not in our scope to train an Artificial Neural Network "ANN", but just to propose a new scheme for IDS based ANN, In our future work we will present all the details related to the architecture and parameters of the ANN, as well as the results of some real experiments.

URLhttps://ieeexplore.ieee.org/document/8942383
DOI10.1109/ICDS47004.2019.8942383
Citation Keyelmaaradi_new_2019