发明名称 |
Method and apparatus for detecting an intrusion on a cloud computing service |
摘要 |
Provided is a method and apparatus for detecting an intrusion in a cloud computing service. An elementary detector may monitor a virtual machine provided by a cloud computing service, and may generate a raw alert based on a result of the monitoring. An intrusion detection system (IDS) dispatcher may determine occurrence of an intrusion into the cloud computing service by comparing the raw alert and a local database. The IDS dispatcher may generate a hyper alert when it is determined that the intrusion has occurred. An intrusion detection system (IDS) manager may determine the occurrence of the intrusion by comparing the hyper alert and a global database. |
申请公布号 |
US9294489(B2) |
申请公布日期 |
2016.03.22 |
申请号 |
US201214345196 |
申请日期 |
2012.09.26 |
申请人 |
INTELLECTUAL DISCOVERY CO., LTD. |
发明人 |
Huh Eui Nam;Na Sang Ho;Park Jun Young;Kim Jin Taek |
分类号 |
H04L29/06;G06F21/55;G06F11/00 |
主分类号 |
H04L29/06 |
代理机构 |
Rothwell, Figg, Ernst & Manbeck, P.C. |
代理人 |
Rothwell, Figg, Ernst & Manbeck, P.C. |
主权项 |
1. An intrusion detection system of a cloud computing service, the system comprising:
one or more processors; a network interface coupled to the one or more processors; and a non-transitory memory coupled to the one or more processors, wherein the one or more processors are configured to: generate an elementary detector to monitor a virtual machine provided by the cloud computing service, wherein the elementary detector comprises a raw alert generator and an encoder, wherein the elementary detector is configured to:
generate, using the raw alert generator, a raw alert based on a result of the monitoring the cloud computing service, wherein the raw alert comprises a supercritical value and a state value of the virtual machine and wherein the supercritical value indicates a level at which a traffic value of the virtual machine exceeds a threshold, and,encrypt, using the encoder, the raw alert containing the intrusion information; and generate an intrusion detection system (IDS) dispatcher, the IDS dispatcher comprising a decoder and an alert correlator, wherein the IDS dispatcher is configured to:
decrypt, using the decoder, the encrypted raw alert; and,determine, using the alert correlator, an occurrence of an intrusion into the cloud computing service based on the decrypted raw alert. |
地址 |
Seoul KR |