Malicious virtual machines detection through a clustering approach

  • Mohammad Bazm
  • , Rida Khatoun
  • , Youcef Begriche
  • , Lyes Khoukhi
  • , Xiuzhen Chen
  • , Ahmed Serhrouchni

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Cloud computing aims to provide enormous resources and services, parallel processing and reliable access for users on the networks. The flexible resources of clouds could be used by malicious actors to attack other infrastructures. Cloud can be used as a platform to perform these attacks, a virtual machine(VM) in the Cloud can play the role of a malicious VM belonging to a Botnet and sends a heavy traffic to the victim. For cloud service providers, preventing their infrastructure from being turned into an attack platform is very challenging since it requires detecting attacks at the source, in a highly dynamic and heterogeneous environment. In this paper, an approach to detect these malicious behaviors in the Cloud based on the analysis of network parameters is proposed. This approach is a source-based attack detection, which applies both Entropy and clustering methods on network parameters. The environment of Cloud is simulated on Cloudsim. The data clustering allows achieving high performance, with a high percentage of correctly clustered VMs.

Original languageEnglish
Title of host publicationProceedings of 2015 International Conference on Cloud Computing Technologies and Applications, CloudTech 2015
EditorsMohamed Essaaidi, Mostapha Zbakh
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronic)9781467381499
DOIs
Publication statusPublished - 24 Nov 2015
Event4th International Conference on Cloud Computing Technologies and Applications, CloudTech 2015 - Marrakech, Morocco
Duration: 2 Jun 20154 Jun 2015

Publication series

NameProceedings of 2015 International Conference on Cloud Computing Technologies and Applications, CloudTech 2015

Conference

Conference4th International Conference on Cloud Computing Technologies and Applications, CloudTech 2015
Country/TerritoryMorocco
CityMarrakech
Period2/06/154/06/15

Keywords

  • Cloud computing
  • DDoS
  • clustering
  • detection
  • entropy

Fingerprint

Dive into the research topics of 'Malicious virtual machines detection through a clustering approach'. Together they form a unique fingerprint.

Cite this