Toward Smart Moving Target Defense for Linux Container Resiliency

Mohamed Azab, Bassem Mokhtar, Amr S. Abed, Mohamed Eltoweissy

Research output: Chapter in Book/Report/Conference proceedingConference contribution

19 Citations (Scopus)

Abstract

This paper presents ESCAPE, an informed moving target defense mechanism for cloud containers. ESCAPE models the interaction between attackers and their target containers as a 'predator searching for a prey' search game. Live migration of Linux-containers (prey) is used to avoid attacks (predator) and failures. The entire process is guided by a novel host-based behavior-monitoring system that seamlessly monitors containers for indications of intrusions and attacks. To evaluate ESCAPE effectiveness, we simulated the attack avoidance process based on a mathematical model mimicking the prey-vs-predator search game. Simulation results show high container survival probabilities with minimal added overhead.

Original languageEnglish
Title of host publicationProceedings - 2016 IEEE 41st Conference on Local Computer Networks, LCN 2016
PublisherIEEE Computer Society
Pages619-622
Number of pages4
ISBN (Electronic)9781509020546
DOIs
Publication statusPublished - Dec 22 2016
Externally publishedYes
Event41st IEEE Conference on Local Computer Networks, LCN 2016 - Dubai, United Arab Emirates
Duration: Nov 7 2016Nov 10 2016

Publication series

NameProceedings - Conference on Local Computer Networks, LCN

Other

Other41st IEEE Conference on Local Computer Networks, LCN 2016
Country/TerritoryUnited Arab Emirates
CityDubai
Period11/7/1611/10/16

Keywords

  • Cloud Security
  • Linux containers
  • Live Migration

ASJC Scopus subject areas

  • Computer Networks and Communications
  • Hardware and Architecture

Fingerprint

Dive into the research topics of 'Toward Smart Moving Target Defense for Linux Container Resiliency'. Together they form a unique fingerprint.

Cite this