Toward scalable graph-based security analysis for cloud networks
نویسندگان
چکیده
Cloud-based systems and services are seeing exponential growth in the last few years. Many companies digital actively migrating their storage computational needs to cloud. With such an expansion of virtual services, security threats also significantly increasing. Utilizing Attack Representation Methods (ARMs) Graph (AG) enables administrator understand cloud network’s current situation. However, AG suffers from scalability challenges. It relies on connectivity between vulnerabilities associated with allow system realize its state. This approach caused be vast challenging generate analyze. To address challenges, we propose a segmentation-based scalable state (S3) framework for network. Our utilizes well-known divide-and-conquer divide large network region into smaller, manageable segments. We follow segmentation derived K-means clustering algorithm partition segments based similarity services. A distributed firewall (DFW) separates ensure attacker cannot move laterally compromise them. evaluation shows that separation not only preserves original reachability but enhances AG. The presented (a) provides attack graph generation by reducing time density, which turn reduces complexity analysis extensive network, (b) ensures loop-free through utilization cycle detection removal algorithm, (c) presents provide optimal number cost implementing using rules.
منابع مشابه
Scalable RDF Graph Querying Using Cloud Computing
With the explosion of the semantic web technologies, conventional SPARQL processing tools do not scale well for large amounts of RDF data because they are designed for use on a single-machine context. Several optimization solutions combined with cloud computing technologies have been proposed to overcome these drawbacks. However, these approaches only consider the SPARQL Basic Graph Pattern pro...
متن کاملToward Scalable Activity Recognition for Sensor Networks
Sensor networks hold the promise of truly intelligent buildings: buildings that adapt to the behavior of their occupants to improve productivity, efficiency, safety, and security. To be practical, such a network must be economical to manufacture, install and maintain. Similarly, the methodology must be efficient and must scale well to very large spaces. Finally, be be widely acceptable, it must...
متن کاملToward Cloud Computing: Security and Performance
Security and performance are basic requirements for any system. They are considered the criteria for the measurement of any progress in a security system. Security is an indicator that affects the level of performance through the threats that influence the performance of parts of the cloud during the rendering of services. Both security and performance demonstrate the efficiency of cloud comput...
متن کاملToward a scalable refinement strategy for multilevel graph repartitioning
Dynamic load balancing is a mandatory feature for parallel software whose workload evolves with time, such as solvers implementing adaptive mesh refinement. In such solvers, problem space is most often represented as an unstructured mesh, and graph partitioning is used to distribute data and their associated computations across processes. The purpose of this paper is to study the sequential ver...
متن کاملScalable multi-layer GMPLS networks based on hierarchical cloud-routers
This paper proposes the hierarchical cloud-router network (HCRN) to solve the problem of overcoming the scalability limit in a multi-layer generalized multi-protocol label switching (GMPLS) network. We define a group of nodes as a virtual node, called cloud-router (CR). A CR consists of some number of nodes or lower-level CRs. A CR is modeled as a multiple switching capability (SC) node when it...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
ژورنال
عنوان ژورنال: Computer Networks
سال: 2022
ISSN: ['1872-7069', '1389-1286']
DOI: https://doi.org/10.1016/j.comnet.2022.108795