基于多风险分析的云网络安全AI驱动虚拟机威胁预测模型

An AI-Driven VM Threat Prediction Model for Multi-Risks Analysis-Based Cloud Cybersecurity

IEEE Transactions on Systems, Man, and Cybernetics: Systems · 2023
被引 50 · 同刊同年前 7%
ABS 3

中文导读

提出一种多风险分析的虚拟机威胁预测模型,通过量化配置、管理及用户行为等风险因素,用机器学习分类器预测威胁概率,在基准数据集上测试可降低88.9%的网络安全威胁。

Abstract

Cloud virtualization technology, ingrained with physical resource sharing, prompts cybersecurity threats on users’ virtual machines (VMs) due to the presence of inevitable vulnerabilities on the offsite servers. Contrary to the existing works which concentrated on reducing resource sharing and encryption/decryption of data before transfer for improving cybersecurity which raises computational cost overhead, the proposed model operates diversely for efficiently serving the same purpose. This article proposes a novel multiple risks analysis-based VM threat prediction model (MR-TPM) to secure computational data and minimize adversary breaches by proactively estimating the VMs threats. It considers multiple cybersecurity risk factors associated with the configuration and management of VMs, along with analysis of users’ behavior. All these threat factors are quantified for the generation of respective risk score values and fed as input into a machine learning-based classifier to estimate the probability of threat for each VM. The performance of MR-TPM is evaluated using benchmark Google Cluster and OpenNebula VM threat traces. The experimental results demonstrate that the proposed model efficiently computes the cybersecurity risks and learns the VM threat patterns from historical and live data samples. The deployment of MR-TPM with existing VM allocation policies reduces cybersecurity threats up to 88.9%.

云计算网络安全虚拟机威胁预测机器学习