Caught-in-Translation (CiT): Detecting Cross-Level Inconsistency Attacks in Network Functions Virtualization (NFV)

计算机科学 事件(粒子物理) 人工智能 抽象 杠杆(统计) 相似性(几何) 图像(数学) 哲学 物理 认识论 量子力学
作者
Sudershan Lakshmanan,Mengyuan Zhang,Suryadipta Majumdar,Yosr Jarraya,Makan Pourzandi,Lingyu Wang
出处
期刊:IEEE Transactions on Dependable and Secure Computing [Institute of Electrical and Electronics Engineers]
卷期号:21 (4): 2964-2981
标识
DOI:10.1109/tdsc.2023.3320811
摘要

As one of the main technology pillars of 5G networks, Network Functions Virtualization (NFV) enables agile and cost-effective deployment of network services. However, the multi-level, multi-actor design of NFV may also allow for inconsistency between the different abstraction levels to be mistakenly or intentionally introduced, as shown in recent studies. Serious security issues, such as man-in-the-middle, network sniffing, and DoS, may arise at one abstraction level without being noticed by the victims at another level. Most existing solutions are either limited to one abstraction level of NFV or reliant on direct access to lower-level data which could become inaccessible when managed by different providers. In this paper, by drawing an analogy between cross-level NFV event sequences and natural languages, we propose a Neural Machine Translation-based approach, namely, Caught-in-Translation (CiT) , to detect cross-level inconsistency attacks in NFV at runtime. Specifically, we first extract event sequences from different abstraction levels of an NFV stack. We then leverage Long Short-Term Memory (LSTM) to translate the event sequences from one level to another. Finally, we apply both a similarity metric and a Siamese neural network to compare the translated event sequences with the original ones to detect attacks. We integrate CiT into OpenStack/Tacker, a popular open-source NFV implementation, and evaluate its performance using both real and synthetic data. Experimental results show the benefit of leveraging NMT as CiT achieves AUC≥96.03%, which significantly outperforms traditional SVM-based anomaly detection. We also evaluate CiT in terms of its efficiency, scalability, and robustness for detecting inconsistency attacks in NFV platforms.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
熊儒恒完成签到,获得积分10
刚刚
不带与你完成签到,获得积分20
刚刚
刚刚
刚刚
1秒前
xxx完成签到 ,获得积分20
1秒前
英姑应助平常茉莉采纳,获得10
1秒前
tang123完成签到,获得积分10
1秒前
量子星尘发布了新的文献求助10
1秒前
2秒前
maplesirup发布了新的文献求助30
2秒前
yyh发布了新的文献求助10
2秒前
2秒前
3秒前
科研通AI6.1应助TTm采纳,获得10
3秒前
是Dannie不是丹尼完成签到,获得积分10
3秒前
3秒前
lumia发布了新的文献求助10
3秒前
3秒前
研友_Z33zkZ发布了新的文献求助10
4秒前
4秒前
英俊的铭应助许十五采纳,获得10
4秒前
田様应助天天看文献采纳,获得10
4秒前
CodeCraft应助leaf采纳,获得10
4秒前
Hanoi347应助oyy318采纳,获得10
4秒前
酷波er应助zz采纳,获得10
4秒前
4秒前
5秒前
费凝海发布了新的文献求助10
5秒前
6秒前
Jasper应助外向寄云采纳,获得10
6秒前
ATTENTION完成签到,获得积分10
6秒前
6秒前
6秒前
mamin完成签到,获得积分20
7秒前
iFreedom发布了新的文献求助10
7秒前
7秒前
木木完成签到,获得积分10
7秒前
季博常完成签到,获得积分10
7秒前
7秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Handbook of pharmaceutical excipients, Ninth edition 5000
Aerospace Standards Index - 2026 ASIN2026 3000
Signals, Systems, and Signal Processing 610
Discrete-Time Signals and Systems 610
Principles of town planning : translating concepts to applications 500
Modified letrozole versus GnRH antagonist protocols in ovarian aging women for IVF: An Open-Label, Multicenter, Randomized Controlled Trial 360
热门求助领域 (近24小时)
化学 材料科学 医学 生物 工程类 纳米技术 有机化学 物理 生物化学 化学工程 计算机科学 复合材料 内科学 催化作用 光电子学 物理化学 电极 冶金 遗传学 细胞生物学
热门帖子
关注 科研通微信公众号,转发送积分 6062548
求助须知:如何正确求助?哪些是违规求助? 7894713
关于积分的说明 16310666
捐赠科研通 5205881
什么是DOI,文献DOI怎么找? 2785030
邀请新用户注册赠送积分活动 1767645
关于科研通互助平台的介绍 1647422