• DocumentCode
    653835
  • Title

    A cloud computing based architecture for cyber security situation awareness

  • Author

    Wei Yu ; Guobin Xu ; Zhijiang Chen ; Moulema, Paul

  • Author_Institution
    Towson Univ., Towson, MD, USA
  • fYear
    2013
  • fDate
    14-16 Oct. 2013
  • Firstpage
    488
  • Lastpage
    492
  • Abstract
    The exponential growth of cyber space has created opportunities for world-wide web-based businesses and information sharing, but also led to the proliferation of cyber attacks. To conduct the cyber security situation awareness, a large volume of data streams from monitored devices needs to be efficiently stored and processed in real time. In this paper, we propose a cloud computing based architecture for conducting cyber security situation awareness. Particularly, we leverage the cloud infrastructure with a cost-effective data storage and investigate efficient stream processing techniques to reduce operational delays. To effectively detect threats, we present a parallel cloud based threat detection that integrates both signature-based detection and anomaly-based detection. To capture the insightful characteristics of attacks, we discuss the attack scene analysis based on spatiotemporal correlation and visualization schemes to analyze, trace, and visualize abnormal behaviors. Lastly, we present the testbed setup and the implementation workflow to validate the effectiveness of our proposed system.
  • Keywords
    Web sites; cloud computing; security of data; World-Wide Web-based businesses; abnormal behavior analysis; abnormal behavior tracing; abnormal behavior visualization; anomaly-based detection; attack characteristics; attack scene analysis; cloud computing based architecture; cloud infrastructure; cost-effective data storage; cyber attack proliferation; cyber security situation awareness; information sharing; parallel cloud based threat detection; real time data stream processing; real time data stream storage; signature-based detection; spatiotemporal correlation and visualization schemes; stream processing techniques; Cloud computing; Computer architecture; Computer security; Data processing; Monitoring; Servers; Cloud Computing; Cyber Security; MapReduce; Situation Awareness;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communications and Network Security (CNS), 2013 IEEE Conference on
  • Conference_Location
    National Harbor, MD
  • Type

    conf

  • DOI
    10.1109/CNS.2013.6682765
  • Filename
    6682765