基于轻量级入侵检测的KubeEdge架构服务可用性改进
Improving Service Availability in KubeEdge-Based Architectures Using Lightweight Intrusion Detection
浏览论文内容
中文总结 AI 辅助
针对KubeEdge边缘架构的安全威胁,提出轻量级入侵检测规则集RIDRS,通过及时检测和缓解DoS攻击及恶意容器部署,显著减少停机时间并提升服务可用性。
中文摘要 AI 辅助
物联网(IoT)和云计算的日益普及加速了边缘计算范式的演进[1]。行业预测估计,到2030年,连接的物联网设备数量将达到约500亿,而到2025年预计将有约380亿连接[34],这将导致数据生成量的空前增长。这一趋势要求在网络边缘实现高效、可扩展且安全的数据处理机制。因此,确保物联网应用和设备的可靠管理与保护已成为一项关键挑战。在此背景下,KubeEdge将云原生能力扩展到边缘环境,实现分布式编排,同时也引入了新的安全问题。本文研究了在物联网驱动和分布式边缘架构中容器镜像的安全性。具体而言,我们分析了主要安全威胁(包括拒绝服务(DoS)攻击和恶意容器部署)对基于KubeEdge系统的可用性和运行稳定性的影响。为应对这些挑战,我们提出了一种针对资源受限边缘环境量身定制的轻量级推荐入侵检测规则集(RIDRS)。所提出的方法通过实现安全威胁的及时检测和缓解,提高了系统的弹性。我们将系统稳定性定义为在对抗条件下维持一致运行行为并自主恢复的能力。实验结果表明,RIDRS显著减少了系统停机时间并增强了服务可用性,特别是在涉及代码注入和恶意Pod部署攻击的场景中。
英文摘要
The increasing adoption of the Internet of Things (IoT) and cloud computing has accelerated the evolution of edge computing paradigms [1]. Industry forecasts estimate that the number of connected IoT devices will reach approximately 50 billion by 2030, following an estimated 38 billion connections by 2025 [34], resulting in an unprecedented growth in data generation. This trend necessitates efficient, scalable, and secure data processing mechanisms at the network edge. Consequently, ensuring the reliable management and protection of IoT applications and devices has become a critical challenge. In this context, KubeEdge extends cloud-native capabilities to edge environments, enabling distributed orchestration while introducing new security concerns. This paper investigates the security of container images in IoT-driven and distributed edge architectures. Specifically, we analyze the impact of major security threats, including Denial of Service (DoS) attacks and malicious container deployments, on the availability and operational stability of KubeEdge-based systems. To address these challenges, we propose a lightweight Recommended Intrusion Detection Rule Set (RIDRS) tailored for resource-constrained edge environments. The proposed approach improves system resilience by enabling timely detection and mitigation of security threats. We define system stability as the ability to maintain consistent operational behavior and to recover autonomously under adversarial conditions. Experimental results demonstrate that RIDRS significantly reduces system downtime and enhances service availability, particularly in scenarios involving code injection and malicious pod deployment attacks.
发表机构
- Laval University(拉瓦尔大学)
机构由 AI 辅助整理,请以论文原文为准。