Ändra sökning
RefereraExporteraLänk till posten
Permanent länk

Direktlänk
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annat format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annat språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf
Ensemble of Random and Isolation Forests for Graph-Based Intrusion Detection in Containers
RISE Research Institutes of Sweden, Digitala system, Datavetenskap.ORCID-id: 0000-0001-6116-164X
RISE Research Institutes of Sweden, Digitala system, Datavetenskap.ORCID-id: 0000-0001-8192-0893
2022 (Engelska)Ingår i: Proceedings of the 2022 IEEE International Conference on Cyber Security and Resilience, CSR 2022, Institute of Electrical and Electronics Engineers Inc. , 2022, s. 30-37Konferensbidrag, Publicerat paper (Refereegranskat)
Abstract [en]

We propose a novel solution combining supervised and unsupervised machine learning models for intrusion detection at kernel level in cloud containers. In particular, the proposed solution is built over an ensemble of random and isolation forests trained on sequences of system calls that are collected at the hosting machine's kernel level. The sequence of system calls are translated into a weighted and directed graph to obtain a compact description of the container behavior, which is given as input to the ensemble model. We executed a set of experiments in a controlled environment in order to test our solution against the two most common threats that have been identified in cloud containers, and our results show that we can achieve high detection rates and low false positives in the tested attacks. 

Ort, förlag, år, upplaga, sidor
Institute of Electrical and Electronics Engineers Inc. , 2022. s. 30-37
Nyckelord [en]
Cloud containers, Intrusion Detection System, Machine learning on Graph, Directed graphs, Forestry, Graphic methods, Intrusion detection, Machine learning, Cloud container, Graph-based, Intrusion Detection Systems, Intrusion-Detection, Machine-learning, Novel solutions, Supervised machine learning, System calls, Unsupervised machine learning, Containers
Nationell ämneskategori
Data- och informationsvetenskap
Identifikatorer
URN: urn:nbn:se:ri:diva-60157DOI: 10.1109/CSR54599.2022.9850307Scopus ID: 2-s2.0-85137367814ISBN: 9781665499521 (tryckt)OAI: oai:DiVA.org:ri-60157DiVA, id: diva2:1702102
Konferens
2nd IEEE International Conference on Cyber Security and Resilience, CSR 2022, 27 July 2022 through 29 July 2022
Anmärkning

 Funding text 1: This research is partially funded by the EU H2020 ARCADIAN-IoT (Grant ID. 101020259) and partly by the H2020 CONCORDIA (Grant ID. 830927).

Tillgänglig från: 2022-10-10 Skapad: 2022-10-10 Senast uppdaterad: 2025-09-23Bibliografiskt granskad

Open Access i DiVA

Fulltext saknas i DiVA

Övriga länkar

Förlagets fulltextScopus

Person

Iacovazzi, AlfonsoRaza, Shahid

Sök vidare i DiVA

Av författaren/redaktören
Iacovazzi, AlfonsoRaza, Shahid
Av organisationen
Datavetenskap
Data- och informationsvetenskap

Sök vidare utanför DiVA

GoogleGoogle Scholar

doi
isbn
urn-nbn

Altmetricpoäng

doi
isbn
urn-nbn
Totalt: 229 träffar
RefereraExporteraLänk till posten
Permanent länk

Direktlänk
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annat format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annat språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf