arrow
Return

Detecting Anomalies Through Sequential Performance Analysis in Virtualized Environments

delete2023-01-01
delete0
delete
OA
AI
C
Charles F. Gonçalves *
D
Daniel Sadoc Menasché
A
Alberto Avritzer
N
Nuno Antunes
M
Marco Vieira
DOI:10.1109/ACCESS.2023.3293643delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Virtualization enables cloud computing, allowing for server consolidation with cost reduction. It also introduces new challenges in terms of security and isolation, which are deterrents for the adoption of virtualization in critical systems. Virtualized systems tend to be very complex, and multi-tenancy is the norm, as the hypervisor manages the resources shared among virtual machines. This paper proposes a methodology that uses performance modeling for the detection of anomalies in virtualized environments that can be caused, for instance, by cyberattacks. Experiments are conducted to profile the system operation under normal conditions for its business transactions. The results are used to calibrate a performance model and to understand the impact of its parameters on the false positive probability. During operation, the system is monitored, and deviations are detected by applying a sequential analysis algorithm (the bucket algorithm). The methodology is evaluated using a representative cloud workload (TPCx-V), which was profiled during a set of controlled executions. We consider resource exhaustion anomalies to emulate the effects of attacks affecting the performance of the system. Our results show that the proposed approach is able to successfully detect anomalies, with a low number of false positives, and spot possible residual effects of anomalies on the system.
Keywords:
Anomaly detection
modeling
performance
security
virtualization

Journal

IEEE Access cover
IEEE Access
IF:
3.6
Papers:
9.7W
Citations:
29.4W

Organization

U
Universidade Federal do Rio de Janeiro
Scholars:
2.9W
Papers: 1.8W
Citations: 1.6W
U
universidade de coimbra
Scholars:
1.9W
Papers: 1.6W
Citations: 16