Today, many organizations are moving their applications towards microservice architecture and virtualized environments because of the benefits such as deployment agility, scalability, flexibility and resiliency. In such complex and dynamic environment where components and connections may be constantly changing, it is difficult to provide a consistent view of the application out of many changing processes and their connections which is necessary for behaviour profiling. Therefore, in this thesis, we define a role identification method for microservices to build a consistent view of microservice-based applications.
Recently, various types of stealthy attacks have been reported against microservice-based applications which are not possible to detect by monitoring a single process or a single microservice. Profiling the behaviour of all microservices of an application as a whole is challenging due to the distributed and non-blocking nature of microservice-based applications. In this thesis, we investigate a data-flow-based approach to overcome these challenges based on our role identification method and propose a graph-based model to represent the behaviour of a microservice-based application that is distributed over multiple hosts. This graph-based representation is then used to extract features providing the appropriate measures to profile the aggregated behaviour of the microservices comprising a microservice-based application.
Machine Learning algorithms, especially Deep Learning (DL) models have shown the state-ofthe- art performances on many anomaly detection tasks. However, DL-based approaches face challenges in accurately identifying the abnormal behaviour of microservice-based applications due to the highly dynamic and heterogeneous characteristics of the cloud which results in a high false alarm rate. Therefore, we propose a microservice-based optimization for DL-based anomaly detection models to decrease the false alarms.
The efficiency and feasibility of our approach are demonstrated through several different realworld attacks against the microservice-based implementation of LTE and IMS networks. The obtained result yields high detection rates (94%-96%) at a very low (0.01%) false alarm rate.
| Date | 7 Dec 2021 |
|---|
| Original language | American English |
|---|
| Awarding Institution | - École de technologie supérieure
|
|---|
| Supervisor | Kim Khoa Nguyen (Supervisor) & Mohamed Cheriet (Co-supervisor) |
|---|
Ghorbani, M. (Author),
Nguyen (Supervisor) &
Cheriet (Co-supervisor),
7 Dec 2021Student thesis: Master's thesis › Master in Engineering: Engineering