Cloud computing is widely used in government and business sectors. For the business sector, security is one of the most important topics to be considered to protect user and confidential data, especially in a cloud, which cannot manage the infrastructure physically. A private cloud is deployed to utilize only in an organization for all internal users. In addition, a Network Intrusion Detection System (NIDS) is normally used for detecting intruders from outside organizations. However, if an attacker is inside a private cloud, a typical NIDS placement cannot detect this type of attack. Therefore, the objective of this study is to design and analyze the NIDS locations to defend against internal attacks on a private cloud. A private cloud was deployed using OpenStack cloud with 3 physical servers, which were one admin/network node, and two compute nodes. Two types of attacks, DDoS and SSH brute force attacks, were implemented. Three NIDS placement scenarios inside the cloud were proposed and experimented with. The results indicated that NIDS placements on a network node, and compute nodes with a tap port, gave the best performance. In this scenario, NIDS detected all internal attacks, and Application VMs responded to requests up to 79.16% without performance reduction.
Anusas-Amornkul et al. (Tue,) studied this question.