Skip to main navigation Skip to search Skip to main content

Detecting anomalous behavior in cloud servers by nested-arc hidden SEMI-markov model with state summarization

  • Waqas Haider
  • , Jiankun Hu*
  • , Yi Xie
  • , Xinghuo Yu
  • , Qianhong Wu
  • *Corresponding author for this work
  • University of New South Wales
  • Sun Yat-Sen University
  • Royal Melbourne Institute of Technology University

Research output: Contribution to journalArticlepeer-review

Abstract

Anomaly detection for cloud servers is important for detecting zero-day attacks. However, it is very challenging due to the large amount of accumulated data. In this paper, a new mathematical model for modeling dynamic usage behavior and detecting anomalies is proposed. It is constructed using state summarization and a novel nested-arc hidden semi-Markov model (NAHSMM). State summarization is designed to extract usage behavior reflective states from a raw sequence. The NAHSMM is comprised of exterior and interior hidden Markov chains. The exterior controls the propagation of raw sequences of system calls and, conditional on it, the interior one controls the summarized observation process from the transition less usage behavior reflective states. An anomaly detection algorithm is derived by integrating state summarization and NAHSMM. During training the algorithm is assisted by a forensic module to tune the behavioral threshold. Experimental data is collected using IXIA Perfect Storm in conjunction with the commercial security-test hardware platform cyber range. To evaluate the reliability of the proposed model, first, its accuracy and training costs are compared with those of existing machine-learning models and then its scalability and resistance capabilities are tested. The results indicate that this model could be used as a method for detecting anomalies in cloud servers.

Original languageEnglish
Article number8003385
Pages (from-to)305-316
Number of pages12
JournalIEEE Transactions on Big Data
Volume5
Issue number3
DOIs
StatePublished - 1 Jul 2019

Keywords

  • Anomaly detection
  • Big data analytic
  • Cyber security
  • HMM
  • IDS
  • Intrusion detection
  • System calls

Fingerprint

Dive into the research topics of 'Detecting anomalous behavior in cloud servers by nested-arc hidden SEMI-markov model with state summarization'. Together they form a unique fingerprint.

Cite this