<p>Intrusion Detection and Prevention Systems (IDPS) play a key role in protecting networks by keeping an eye out for suspicious activity, spotting threats, and taking action to stop them. These systems were originally designed for traditional, fixed networks, but they struggle to keep up with the fast-paced and constantly changing nature of cloud computing environments. Cloud computing has revolutionized technology, bringing many innovations in how organizations operate. Organizations rely heavily on the use of cloud storage to store and retrieve their sensitive data. Security issues in the cloud computing environment are a big challenge as, despite various protection measures, the cloud environment is vulnerable to security threats. Intrusion Detection and Prevention System (IDPS) is a significant component in securing the cloud environment against emerging threats in cyber-attacks. This paper takes a close look at intrusion detection systems (IDS) that are specifically built for cloud computing. The cloud brings its own set of challenges like constantly changing resources, sharing space between many users, and limited visibility into all the network traffic. Unlike traditional IDS that work in fixed, local networks, cloud-based IDS have to handle traffic that moves between virtual machines and scale up or down quickly. Cloud computing has transformed over time, improving access to scalability while offering vulnerabilities that increase the probability of intrusion or attacks. This review addresses these research gaps by comprehensively surveying state-of-the-art IDPS techniques tailored for cloud computing environments. IDPS is further classified into different categories, such as signature-based, anomaly-based, and hybrid-based. Recently, combining Machine Learning (ML) and Deep Learning (DL) with Intrusion Detection Systems (IDS) has shown to be very effective, as it allows for more precise detection and large-scale use. However, notable challenges include small dataset sizes, imbalanced datasets, and high expenses. These challenges mainly focus on creating adaptive systems that identify intrusions in real time. To tackle this, attention is directed towards ensemble learning and edge computing. The outcomes of these initiatives are being used to create a strong and efficient IDS that fits well with the changing nature of cloud environments. This survey provides a comprehensive analysis of current IDPS methodologies and future perspectives, aiming to contribute to developing robust and efficient cloud security solutions.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A systematic literature review on intrusion detection techniques in cloud computing

  • Shamma Shabnam Nasim,
  • Prashant Pranav,
  • Sandip Dutta

摘要

Intrusion Detection and Prevention Systems (IDPS) play a key role in protecting networks by keeping an eye out for suspicious activity, spotting threats, and taking action to stop them. These systems were originally designed for traditional, fixed networks, but they struggle to keep up with the fast-paced and constantly changing nature of cloud computing environments. Cloud computing has revolutionized technology, bringing many innovations in how organizations operate. Organizations rely heavily on the use of cloud storage to store and retrieve their sensitive data. Security issues in the cloud computing environment are a big challenge as, despite various protection measures, the cloud environment is vulnerable to security threats. Intrusion Detection and Prevention System (IDPS) is a significant component in securing the cloud environment against emerging threats in cyber-attacks. This paper takes a close look at intrusion detection systems (IDS) that are specifically built for cloud computing. The cloud brings its own set of challenges like constantly changing resources, sharing space between many users, and limited visibility into all the network traffic. Unlike traditional IDS that work in fixed, local networks, cloud-based IDS have to handle traffic that moves between virtual machines and scale up or down quickly. Cloud computing has transformed over time, improving access to scalability while offering vulnerabilities that increase the probability of intrusion or attacks. This review addresses these research gaps by comprehensively surveying state-of-the-art IDPS techniques tailored for cloud computing environments. IDPS is further classified into different categories, such as signature-based, anomaly-based, and hybrid-based. Recently, combining Machine Learning (ML) and Deep Learning (DL) with Intrusion Detection Systems (IDS) has shown to be very effective, as it allows for more precise detection and large-scale use. However, notable challenges include small dataset sizes, imbalanced datasets, and high expenses. These challenges mainly focus on creating adaptive systems that identify intrusions in real time. To tackle this, attention is directed towards ensemble learning and edge computing. The outcomes of these initiatives are being used to create a strong and efficient IDS that fits well with the changing nature of cloud environments. This survey provides a comprehensive analysis of current IDPS methodologies and future perspectives, aiming to contribute to developing robust and efficient cloud security solutions.