arrow
返回

Cryptomining Detection in Container Clouds Using System Calls and Explainable Machine Learning

delete2021-03-01
delete50
delete
OA
AI
R
Rupesh Raj Karn
P
Prabhakar Kudva
H
Hai Huang
S
Sahil Suneja
E
Elfadel, Ibrahim (Abe) M. *
DOI:10.1109/TPDS.2020.3029088delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
The use of containers in cloud computing has been steadily increasing. With the emergence of Kubernetes, the management of applications inside containers (or pods) is simplified. Kubernetes allows automated actions like self-healing, scaling, rolling back, and updates for the application management. At the same time, security threats have also evolved with attacks on pods to perform malicious actions. Out of several recent malware types, cryptomining has emerged as one of the most serious threats with its hijacking of server resources for cryptocurrency mining. During application deployment and execution in the pod, a cryptomining process, started by a hidden malware executable can be run in the background, and a method to detect malicious cryptomining software running inside Kubernetes pods is needed. One feasible strategy is to use machine learning (ML) to identify and classify pods based on whether or not they contain a running process of cryptomining. In addition to such detection, the system administrator will need an explanation as to the reason(s) of the MLs classification outcome. The explanation will justify and support disruptive administrative decisions such as pod removal or its restart with a new image. In this article, we describe the design and implementation of an ML-based detection system of anomalous pods in a Kubernetes cluster by monitoring Linux-kernel system calls (syscalls). Several types of cryptominers images are used as containers within an anomalous pod, and several ML models are built to detect such pods in the presence of numerous healthy cloud workloads. Explainability is provided using SHAP, LIME, and a novel auto-encoding-based scheme for LSTM models. Seven evaluation metrics are used to compare and contrast the explainable models of the proposed ML cryptomining detection engine.
Keyword:
Containers
Cloud computing
Malware
Machine learning
Cryptocurrency
Data mining
Cryptomining
docker
kubernetes
containers
machine learning
explainability
pod
anomaly
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

IEEE Transactions on Parallel and Distributed Systems 封面图
IEEE Transactions on Parallel and Distributed Systems
IF:
6
论文数:
5.2K
被引数:
1.1W

机构

I
international business machines (ibm)
学者数:
5.7K
论文数: 4.5K
被引数: 4
引用论文

引用论文

Self-Face Recognition Begins to Share Active Region in Right Inferior Parietal Lobule with Proprioceptive Illusion During Adolescence
err2018-02-06
err0
errOAAI
errTomoyo Morita; Daisuke N Saito; Midori Ban; Koji Shimada; Yuko Okamoto; Hirotaka Kosaka; Hidehiko Okazawa; Minoru Asada; Eiichi Naito
err分享
err收藏
err分享
err收藏
Internal bias field in TGS crystals doped with different impurities
err2004-01-01
err0
PREAI
errA. S. Sidorkin; S. D. Milovidova; O. V. Rogazinskaya; A. A. Sidorkin
err分享
err收藏
err分享
err收藏
A Survey on Ensemble Learning for Data Stream Classification面向数据流分类的集成学习研究综述
err2017-03-27
err378
PREAI
errGomes, Heitor Murilo; Barddal, Jean Paul; Enembreck, Fabricio; Bifet, Albert
err分享
err收藏
err分享
err收藏
REAL-TIME PREDICTIVE CONTROL OF HYBRID FUEL CELL DRIVE TRAINS
err2007-01-01
err0
errOAAI
errRalf Bartholomaeus; Andreas Fischer; Matthias Klingner
err分享
err收藏
err分享
err收藏
学者 查看更多内容