{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,7,2]],"date-time":"2025-07-02T00:40:10Z","timestamp":1751416810279,"version":"3.41.0"},"publisher-location":"Cham","reference-count":50,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319766867"},{"type":"electronic","value":"9783319766874"}],"license":[{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018]]},"DOI":"10.1007\/978-3-319-76687-4_10","type":"book-chapter","created":{"date-parts":[[2018,2,23]],"date-time":"2018-02-23T09:02:09Z","timestamp":1519376529000},"page":"140-155","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["A Study of Threat Detection Systems and\u00a0Techniques in the Cloud"],"prefix":"10.1007","author":[{"given":"Pamela","family":"Carvallo","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ana R.","family":"Cavalli","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Natalia","family":"Kushik","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2018,2,24]]},"reference":[{"key":"10_CR1","unstructured":"Akamai: Akamai\u2019s state of the internet\/Security Q3 2015 report. Technical report (2015)"},{"key":"10_CR2","doi-asserted-by":"crossref","unstructured":"Ateniese, G., Burns, R., Curtmola, R., Herring, J., Kissner, L., Peterson, Z., Song, D.: Provable data possession at untrusted stores. In: Proceedings of the 14th ACM Conference on Computer and Communications Security, CCS 2007 (2007)","DOI":"10.1145\/1315245.1315318"},{"key":"10_CR3","doi-asserted-by":"crossref","unstructured":"Baig, Z.A., Binbeshr, F.: Controlled virtual resource access to mitigate economic denial of sustainability (EDoS) attacks against cloud infrastructures. In: 2013 International Conference on Cloud Computing and Big Data (CloudCom-Asia), pp. 346\u2013353 (2013)","DOI":"10.1109\/CLOUDCOM-ASIA.2013.51"},{"key":"10_CR4","doi-asserted-by":"crossref","unstructured":"Bates, A., Mood, B., Pletcher, J., Pruse, H., Valafar, M., Butler, K.: Detecting co-residency with active traffic analysis techniques. In: CCSW 2012, pp. 1\u201312. ACM Press, New York (2012)","DOI":"10.1145\/2381913.2381915"},{"key":"10_CR5","doi-asserted-by":"crossref","unstructured":"Cao, J., Yu, B., Dong, F., Zhu, X., Xu, S.: Entropy-based denial of service attack detection in cloud data center. In: 2014 Second International Conference on Advanced Cloud and Big Data, pp. 201\u2013207, November 2014","DOI":"10.1109\/CBD.2014.34"},{"key":"10_CR6","volume-title":"Snort 2.0 Intrusion Detection","author":"B Caswell","year":"2003","unstructured":"Caswell, B., Foster, J.C., Russell, R., Beale, J., Posluns, J.: Snort 2.0 Intrusion Detection. Syngress Publishing, Rockland (2003)"},{"key":"10_CR7","doi-asserted-by":"crossref","unstructured":"Chou, H.H., Wang, S.D.: An adaptive network intrusion detection approach for the cloud environment. In: 2015 International Carnahan Conference on Security Technology (ICCST), pp. 1\u20136. IEEE (2015)","DOI":"10.1109\/CCST.2015.7389649"},{"key":"10_CR8","unstructured":"Cloud Security Alliance (CSA): The Notorious Nine: Cloud Computing Top Threats in 2013 (2013)"},{"key":"10_CR9","series-title":"Advances in Intelligent Systems and Computing","doi-asserted-by":"publisher","first-page":"411","DOI":"10.1007\/978-3-319-46568-5_42","volume-title":"Europe and MENA Cooperation Advances in Information and Communication Technologies","author":"M Derfouf","year":"2017","unstructured":"Derfouf, M., Eleuldj, M., Enniari, S., Diouri, O.: Smart intrusion detection model for the cloud computing. In: Rocha, \u00c1., Serrhini, M., Felgueiras, C. (eds.) Europe and MENA Cooperation Advances in Information and Communication Technologies. AISC, vol. 520, pp. 411\u2013421. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-46568-5_42"},{"key":"10_CR10","unstructured":"ENISA: ENISA Threat Landscape 2015. Technical report, January 2016"},{"issue":"4","key":"10_CR11","doi-asserted-by":"crossref","first-page":"15","DOI":"10.1145\/2699909","volume":"17","author":"CC Erway","year":"2015","unstructured":"Erway, C.C., K\u00fcp\u00e7\u00fc, A., Papamanthou, C., Tamassia, R.: Dynamic provable data possession. ACM Trans. Inf. Syst. Secur. (TISSEC) 17(4), 15 (2015)","journal-title":"ACM Trans. Inf. Syst. Secur. (TISSEC)"},{"key":"10_CR12","doi-asserted-by":"crossref","first-page":"113","DOI":"10.1007\/s10207-013-0208-7","volume":"13","author":"DAB Fernandes","year":"2014","unstructured":"Fernandes, D.A.B., Soares, L.F.B., Gomes, J.V., Freire, M.M., In\u00e1cio, P.R.M.: Security issues in cloud environments: a survey. Int. J. Inf. Secur. 13, 113\u2013170 (2014)","journal-title":"Int. J. Inf. Secur."},{"key":"10_CR13","doi-asserted-by":"crossref","first-page":"100","DOI":"10.1016\/j.cose.2014.05.011","volume":"45","author":"S Garc\u00eda","year":"2014","unstructured":"Garc\u00eda, S., Grill, M., Stiborek, J., Zunino, A.: An empirical comparison of botnet detection methods. Comput. Secur. 45, 100\u2013123 (2014)","journal-title":"Comput. Secur."},{"key":"10_CR14","doi-asserted-by":"crossref","unstructured":"Garkoti, G., Peddoju, S.K., Balasubramanian, R.: Detection of insider attacks in cloud based e-healthcare environment. In: 2014 International Conference on Information Technology (ICIT), pp. 195\u2013200. IEEE (2014)","DOI":"10.1109\/ICIT.2014.43"},{"key":"10_CR15","doi-asserted-by":"crossref","unstructured":"Gupta, S., Kumar, P., Sardana, A., Abraham, A.: A fingerprinting system calls approach for intrusion detection in a cloud environment. In: 2012 Fourth International Conference on Computational Aspects of Social Networks (CASoN), pp. 309\u2013314. IEEE (2012)","DOI":"10.1109\/CASoN.2012.6412420"},{"key":"10_CR16","doi-asserted-by":"crossref","unstructured":"Hamdi, O., Mbaye, M., Krief, F.: A cloud-based architecture for network attack signature learning. In: 2015 7th International Conference on New Technologies, Mobility and Security (NTMS). IEEE (2015)","DOI":"10.1109\/NTMS.2015.7266461"},{"issue":"1","key":"10_CR17","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1186\/1869-0238-4-5","volume":"4","author":"K Hashizume","year":"2013","unstructured":"Hashizume, K., Rosado, D.G., Fern\u00e1ndez-Medina, E., Fernandez, E.B.: An analysis of security issues for cloud computing. J. Internet Serv. Appl. 4(1), 5 (2013)","journal-title":"J. Internet Serv. Appl."},{"key":"10_CR18","doi-asserted-by":"crossref","unstructured":"Huang, S.Y., Suri, N., Huang, Y.: Event pattern discovery on IDS traces of cloud services. In: 2014 IEEE International Conference on Big Data and Cloud Computing (BdCloud), pp. 25\u201332. IEEE (2014)","DOI":"10.1109\/BDCloud.2014.92"},{"key":"10_CR19","doi-asserted-by":"crossref","first-page":"736","DOI":"10.1016\/j.future.2015.06.005","volume":"56","author":"T Huang","year":"2016","unstructured":"Huang, T., Zhu, Y., Wu, Y., Bressan, S., Dobbie, G.: Anomaly detection and identification scheme for VM live migration in cloud infrastructure. Future Gener. Comput. Syst. 56, 736\u2013745 (2016)","journal-title":"Future Gener. Comput. Syst."},{"key":"10_CR20","doi-asserted-by":"crossref","first-page":"179","DOI":"10.1016\/j.procs.2015.12.010","volume":"73","author":"H Idrissi","year":"2015","unstructured":"Idrissi, H., Hajji, S.E., Ennahbaoui, M., Souidi, E.M., Souidi, E.M.: Mobile agents with cryptographic traces for intrusion detection in the cloud computing. Procedia Comput. Sci. 73, 179\u2013186 (2015)","journal-title":"Procedia Comput. Sci."},{"issue":"2","key":"10_CR21","first-page":"110","volume":"5","author":"N Jeyanthi","year":"2013","unstructured":"Jeyanthi, N., Iyengar, N.C.S.N., Kumar, P.C.M., Kannammal, A.: An enhanced entropy approach to detect and prevent DDoS in cloud environment. IJCNIS 5(2), 110 (2013)","journal-title":"IJCNIS"},{"key":"10_CR22","doi-asserted-by":"crossref","unstructured":"Jouad, M., Diouani, S., Houmani, H., Zaki, A.: Security challenges in intrusion detection. In: 2015 International Conference on Cloud Technologies and Applications (CloudTech), pp. 1\u201311. IEEE (2015)","DOI":"10.1109\/CloudTech.2015.7337012"},{"key":"10_CR23","doi-asserted-by":"crossref","first-page":"137","DOI":"10.1016\/j.ins.2013.10.005","volume":"262","author":"G Katz","year":"2014","unstructured":"Katz, G., Elovici, Y., Shapira, B.: CoBAn: a context based model for data leakage prevention. Inf. Sci.: Int. J. 262, 137\u2013158 (2014)","journal-title":"Inf. Sci.: Int. J."},{"key":"10_CR24","doi-asserted-by":"crossref","unstructured":"Kene, S.G., Theng, D.P.: A review on intrusion detection techniques for cloud computing and security challenges. In: 2015 2nd International Conference on Electronics and Communication Systems (ICECS), pp. 227\u2013232. IEEE (2015)","DOI":"10.1109\/ECS.2015.7124898"},{"key":"10_CR25","doi-asserted-by":"crossref","unstructured":"Kholidy, H.A., Baiardi, F.: CIDS: a framework for intrusion detection in cloud systems. In: 2012 Ninth International Conference on Information Technology: New Generations (ITNG). IEEE (2012)","DOI":"10.1109\/ITNG.2012.94"},{"issue":"6","key":"10_CR26","doi-asserted-by":"crossref","first-page":"833","DOI":"10.1016\/j.future.2012.01.006","volume":"28","author":"MT Khorshed","year":"2012","unstructured":"Khorshed, M.T., Ali, A.B.M.S., Wasimi, S.A.: A survey on gaps, threat remediation challenges and some thoughts for proactive attack detection in cloud computing. Future Gener. Comput. Syst. 28(6), 833\u2013851 (2012)","journal-title":"Future Gener. Comput. Syst."},{"key":"10_CR27","unstructured":"Kingma, D.P., Ba, J.: Adam: a method for stochastic optimization. CoRR (2014)"},{"key":"10_CR28","doi-asserted-by":"crossref","unstructured":"Kumar, N., Katta, V., Mishra, H., Garg, H.: Detection of data leakage in cloud computing environment. In: 2014 International Conference on Computational Intelligence and Communication Networks (CICN), pp. 803\u2013807. IEEE (2014)","DOI":"10.1109\/CICN.2014.172"},{"key":"10_CR29","doi-asserted-by":"crossref","unstructured":"Li, Y.H., Tzeng, Y.R., Yu, F.: VISO: characterizing malicious behaviors of virtual machines with unsupervised clustering. In: 2015 IEEE 7th International Conference on Cloud Computing Technology and Science (CloudCom). IEEE (2015)","DOI":"10.1109\/CloudCom.2015.19"},{"key":"10_CR30","doi-asserted-by":"crossref","unstructured":"Marnerides, A.K., Spachos, P., Chatzimisios, P., Mauthe, A.U.: Malware detection in the cloud under ensemble empirical mode decomposition. In: 2015 International Conference on Computing, Networking and Communications (ICNC), pp. 82\u201388. IEEE (2015)","DOI":"10.1109\/ICCNC.2015.7069320"},{"key":"10_CR31","unstructured":"Marnerides, A.K., Shirazi, N., Hutchison, D., Simpson, S., Watson, M., Mauthe, A.: Assessing the impact of intra-cloud live migration on anomaly detection. In: 2014 IEEE 3rd International Conference on Cloud Networking (CloudNet) (2014)"},{"key":"10_CR32","doi-asserted-by":"crossref","unstructured":"Mell, P.M., Grance, T.: SP 800\u2013145. The NIST Definition of Cloud Computing. Technical report, Gaithersburg, MD, USA (2011)","DOI":"10.6028\/NIST.SP.800-145"},{"key":"10_CR33","doi-asserted-by":"crossref","unstructured":"Modi, C.N., Patel, D.: A novel hybrid-network intrusion detection system (H-NIDS) in cloud computing. In: 2013 IEEE Symposium on Computational Intelligence in Cyber Security (CICS), pp. 23\u201330 (2013)","DOI":"10.1109\/CICYBS.2013.6597201"},{"issue":"1","key":"10_CR34","doi-asserted-by":"crossref","first-page":"42","DOI":"10.1016\/j.jnca.2012.05.003","volume":"36","author":"C Modi","year":"2013","unstructured":"Modi, C., Patel, D.R., Borisaniya, B., Patel, H., Patel, A., Rajarajan, M.: A survey of intrusion detection techniques in cloud. JNCA 36(1), 42\u201357 (2013)","journal-title":"JNCA"},{"key":"10_CR35","doi-asserted-by":"crossref","first-page":"147","DOI":"10.1016\/j.jnca.2016.01.001","volume":"67","author":"O Osanaiye","year":"2016","unstructured":"Osanaiye, O., Choo, K.K.R., Dlodlo, M.: Distributed denial of service (DDoS) resilience in cloud: review and conceptual cloud DDoS mitigation framework. J. Netw. Comput. Appl. 67, 147\u2013165 (2016)","journal-title":"J. Netw. Comput. Appl."},{"key":"10_CR36","first-page":"1","volume":"21","author":"N Pandeeswari","year":"2015","unstructured":"Pandeeswari, N., Kumar, G.: Anomaly detection system in cloud environment using fuzzy clustering based ANN. Mob. Netw. Appl. 21, 1\u201312 (2015)","journal-title":"Mob. Netw. Appl."},{"issue":"1","key":"10_CR37","doi-asserted-by":"crossref","first-page":"25","DOI":"10.1016\/j.jnca.2012.08.007","volume":"36","author":"A Patel","year":"2013","unstructured":"Patel, A., Taghavi, M., Bakhtiyari, K., Celestino J\u00fanior, J.: An intrusion detection and prevention system in cloud computing: a systematic review. J. Netw. Comput. Appl. 36(1), 25\u201341 (2013)","journal-title":"J. Netw. Comput. Appl."},{"issue":"4","key":"10_CR38","doi-asserted-by":"crossref","first-page":"469","DOI":"10.3390\/fi4020469","volume":"4","author":"DG Rosado","year":"2012","unstructured":"Rosado, D.G., G\u00f3mez, R., Mellado, D., Fern\u00e1ndez-Medina, E.: Security analysis in the migration to cloud environments. Future Internet 4(4), 469\u2013487 (2012)","journal-title":"Future Internet"},{"key":"10_CR39","doi-asserted-by":"crossref","unstructured":"Sculley, D.: Web-scale k-means clustering. In: Proceedings of the 19th International Conference on World Wide Web. In: WWW 2010, pp. 1177\u20131178. ACM (2010)","DOI":"10.1145\/1772690.1772862"},{"issue":"9","key":"10_CR40","first-page":"43","volume":"6","author":"P Shamsolmoali","year":"2014","unstructured":"Shamsolmoali, P., Alam, M.A., Biswas, R.: C2DF: high Rate DDOS filtering method in cloud computing. Int. J. Comput. Netw. Inf. Secur. 6(9), 43\u201350 (2014)","journal-title":"Int. J. Comput. Netw. Inf. Secur."},{"key":"10_CR41","doi-asserted-by":"crossref","unstructured":"Sharma, P., Sharma, R., Pilli, E.S., Mishra, A.K.: A detection algorithm for DoS attack in the cloud environment. In: Compute 2015, pp. 107\u2013110 (2015)","DOI":"10.1145\/2835043.2835052"},{"key":"10_CR42","doi-asserted-by":"crossref","unstructured":"Shirazi, S.N., Simpson, S., Gouglidis, A., Mauthe, A., Hutchison, D.: Anomaly detection in the cloud using data density. In: 2016 IEEE 9th International Conference on Cloud Computing (CLOUD), pp. 616\u2013623, June 2016","DOI":"10.1109\/CLOUD.2016.0087"},{"issue":"1","key":"10_CR43","doi-asserted-by":"crossref","first-page":"93","DOI":"10.1007\/s00607-010-0140-x","volume":"91","author":"LM Vaquero","year":"2011","unstructured":"Vaquero, L.M., Rodero-Merino, L., Mor\u00e1n, D.: Locking the sky: a survey on IaaS cloud security. Computing 91(1), 93\u2013118 (2011)","journal-title":"Computing"},{"issue":"4","key":"10_CR44","doi-asserted-by":"crossref","first-page":"33","DOI":"10.1145\/2716260","volume":"47","author":"E Vasilomanolakis","year":"2015","unstructured":"Vasilomanolakis, E., Karuppayah, S., M\u00fchlh\u00e4user, M., Fischer, M.: Taxonomy and survey of collaborative intrusion detection. CSUR 47(4), 33 (2015). Article no. 55","journal-title":"CSUR"},{"issue":"2","key":"10_CR45","first-page":"192","volume":"13","author":"MR Watson","year":"2016","unstructured":"Watson, M.R., Shirazi, N., Marnerides, A.K., Mauthe, A., Hutchison, D.: Malware detection in cloud computing infrastructures. TDSC 13(2), 192\u2013205 (2016)","journal-title":"TDSC"},{"key":"10_CR46","doi-asserted-by":"crossref","first-page":"403","DOI":"10.1016\/j.ins.2013.04.009","volume":"258","author":"W Xiong","year":"2014","unstructured":"Xiong, W., Hu, H., Xiong, N., Yang, L.T., Peng, W.C., Wang, X., Qu, Y.: Anomaly secure detection methods by analyzing dynamic characteristics of the network traffic in cloud communications. Inf. Sci. 258, 403\u2013415 (2014)","journal-title":"Inf. Sci."},{"key":"10_CR47","doi-asserted-by":"crossref","first-page":"1132","DOI":"10.1002\/sec.1405","volume":"9","author":"Q Yaseen","year":"2016","unstructured":"Yaseen, Q., Althebyan, Q., Panda, B., Jararweh, Y.: Mitigating insider threat in cloud relational databases. Secur. Commun. Netw. 9, 1132\u20131145 (2016)","journal-title":"Secur. Commun. Netw."},{"key":"10_CR48","doi-asserted-by":"crossref","unstructured":"Yu, S., Gui, X., Lin, J.: An approach with two-stage mode to detect cache-based side channel attacks. In: 2013 International Conference on Information Networking (ICOIN), pp. 186\u2013191. IEEE (2013)","DOI":"10.1109\/ICOIN.2013.6496374"},{"key":"10_CR49","doi-asserted-by":"crossref","unstructured":"Yu, W., Moulema, P., Xu, G., Chen, Z.: A cloud computing based architecture for cyber security situation awareness. In: 2013 IEEE Conference on Communications and Network Security (CNS), pp. 488\u2013492. IEEE (2013)","DOI":"10.1109\/CNS.2013.6682765"},{"key":"10_CR50","doi-asserted-by":"crossref","unstructured":"Zbakh, M., Elmahdi, K., Cherkaoui, R., Enniari, S.: A multi-criteria analysis of intrusion detection architectures in cloud environments. In: 2015 International Conference on Cloud Technologies and Applications (CloudTech), pp. 1\u20139. IEEE (2015)","DOI":"10.1109\/CloudTech.2015.7336967"}],"container-title":["Lecture Notes in Computer Science","Risks and Security of Internet and Systems"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-76687-4_10","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,2]],"date-time":"2025-07-02T00:10:11Z","timestamp":1751415011000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-76687-4_10"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018]]},"ISBN":["9783319766867","9783319766874"],"references-count":50,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-76687-4_10","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2018]]}}}