Lateral Movement Identification in Cross-Cloud Deployment | IEEE Conference Publication | IEEE Xplore

Lateral Movement Identification in Cross-Cloud Deployment


Abstract:

In the cloud computing era, cross-cloud deployments enable organizations to operate across multiple autonomous cloud platforms, offering advantages such as resilience, co...Show More

Abstract:

In the cloud computing era, cross-cloud deployments enable organizations to operate across multiple autonomous cloud platforms, offering advantages such as resilience, cost and performance optimization. However, lateral movement attacks, which are critical in the progression of Advanced Persistent Threats (APTs), pose significant challenges in this environment. This paper proposes a Lateral Movement Identification (LMD) system to identify lateral movement attacks in cross-cloud containerized environments. The LMD system utilizes Dynamic Information Flow Tracking (DIFT) and extended Berkeley Packet Filter (eBPF) sandboxes to monitor and associate network traffic within container host kernel without kernel modification. Our experiments validate the efficiency of the LMD system in tracking ingress and egress traffic, differentiating between multiple simultaneous connections, and maintaining minimal performance overhead.
Date of Conference: 28-31 October 2024
Date Added to IEEE Xplore: 31 December 2024
ISBN Information:

ISSN Information:

Conference Location: Prague, Czech Republic

I. Introduction

In the cloud computing era, cross-cloud deployments are designed to operate across multiple autonomous cloud platforms rather than being confined to a single provider. Such deployments offer several advantages for organizations [1]. First, they enhance resilience and availability by enabling failover to alternative providers during outages or disruptions. Cost optimization is another benefit, as organizations can select the most cost-effective services from each provider on the spot. Furthermore, they optimize performance by leveraging the geographic reach of various providers.

Contact IEEE to Subscribe

References

References is not available for this document.