{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/101310"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/101310","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Proactive abuse prevention in clouds","abstract":"Modern day commercial clouds are subject to various forms of infrastructural abuse. Whether it is SaaS, PaaS or IaaS model, attackers and cybercriminals are exploiting clouds to service their needs and using them as a platform to launch attacks and conduct illegal practices. Resultantly, instances where clouds are the source of a malicious or damaging activity have recently spiked. Unlike externally-sourced attacks on clouds, abuse arising from 'within' presents new challenges. This thesis highlights the emerging problem of cloud abuse and attempts to address these challenges. In particular, we argue for a new approach to cloud security that mitigates abuse proactively before the damage is done. Current defense mechanisms are ill-suited as they are primarily designed to mitigate incoming attacks, where the cloud is the target of the attack. Outbound traffic and resource usage is seldom scrutinized for malicious and illegal activities. Furthermore, in-VM security software, such as anti-viruses and intrusion detection systems fail to provide adequate protection as they can be bypassed (using polymorphism, stealth etc.), hidden from (as in virtualization-aware rootkits) or altogether turned off (by getting root access). To make matters worse, hackers have invented automated mechanisms that exploit the freemium business model, allowing them to engineer large pools of resources by combining together the free tier supply. Potentially infinite storage banks and cryptocurrency mining farms with huge distributed footprints have been exposed on top of complimentary services offered by various Cloud Service Providers (CSPs). This has incentivized hackers further, as they can launch lucrative attacks, such as DDoS attacks and spamming, free of cost. Providers struggle to detect this abuse as they lack the necessary tools and infrastructure for proactive detection and mitigation. Currently, all parties (users and providers) are made aware of the abuse when the damage has already been done and different losses have been incurred either by the user or, as in most cases, the provider. These issues highlight the need for new security mechanisms specifically designed to target attacks originating from within the cloud. Hence, in this thesis, we present the design and implementation of an infrastructure that can prove to be useful in proactively thwarting a diverse range of cloud abuse. From break-ins and cryptocurrency mining to DDoS attacks and covert/side channels, the presented infrastructure has the potential to mitigate malicious activity across the spectrum with high accuracy and low overheads without compromising scalability or modularity. We argue that clouds need systems that can react to various forms of abuse by deploying VM-oblivious defenses and minimize co-residency between tenants by making deployments more mobile. Specifically, we present the design of monitors leveraging the lower layers of the cloud-stack, such as the hardware and hypervisor. Furthermore, we also provide meaningful strategies to dynamically reposition entire deployments to minimize the sharing of infrastructure between co-resident tenants. The systems discussed herein add to the security toolbox available to providers and assist them in detecting and mitigating resource abuse in its early stages.","abstract_html":"Modern day commercial clouds are subject to various forms of infrastructural abuse. Whether it is SaaS, PaaS or IaaS model, attackers and cybercriminals are exploiting clouds to service their needs and using them as a platform to launch attacks and conduct illegal practices. Resultantly, instances where clouds are the source of a malicious or damaging activity have recently spiked. Unlike externally-sourced attacks on clouds, abuse arising from &#x27;within&#x27; presents new challenges. This thesis highlights the emerging problem of cloud abuse and attempts to address these challenges. In particular, we argue for a new approach to cloud security that mitigates abuse proactively before the damage is done. Current defense mechanisms are ill-suited as they are primarily designed to mitigate incoming attacks, where the cloud is the target of the attack. Outbound traffic and resource usage is seldom scrutinized for malicious and illegal activities. Furthermore, in-VM security software, such as anti-viruses and intrusion detection systems fail to provide adequate protection as they can be bypassed (using polymorphism, stealth etc.), hidden from (as in virtualization-aware rootkits) or altogether turned off (by getting root access). To make matters worse, hackers have invented automated mechanisms that exploit the freemium business model, allowing them to engineer large pools of resources by combining together the free tier supply. Potentially infinite storage banks and cryptocurrency mining farms with huge distributed footprints have been exposed on top of complimentary services offered by various Cloud Service Providers (CSPs). This has incentivized hackers further, as they can launch lucrative attacks, such as DDoS attacks and spamming, free of cost. Providers struggle to detect this abuse as they lack the necessary tools and infrastructure for proactive detection and mitigation. Currently, all parties (users and providers) are made aware of the abuse when the damage has already been done and different losses have been incurred either by the user or, as in most cases, the provider. These issues highlight the need for new security mechanisms specifically designed to target attacks originating from within the cloud. Hence, in this thesis, we present the design and implementation of an infrastructure that can prove to be useful in proactively thwarting a diverse range of cloud abuse. From break-ins and cryptocurrency mining to DDoS attacks and covert/side channels, the presented infrastructure has the potential to mitigate malicious activity across the spectrum with high accuracy and low overheads without compromising scalability or modularity. We argue that clouds need systems that can react to various forms of abuse by deploying VM-oblivious defenses and minimize co-residency between tenants by making deployments more mobile. Specifically, we present the design of monitors leveraging the lower layers of the cloud-stack, such as the hardware and hypervisor. Furthermore, we also provide meaningful strategies to dynamically reposition entire deployments to minimize the sharing of infrastructure between co-resident tenants. The systems discussed herein add to the security toolbox available to providers and assist them in detecting and mitigating resource abuse in its early stages.","abstract_has_math":false,"creators":["Tahir, Rashid"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"Ph.D.","degree_level":"Dissertation","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":["Caesar, Matthew","Gunter, Carl","Borisov, Nikita","Zaffar, Fareed"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2018,"date_issued":"2018-09-04T20:47:12Z","date_published":"2018-09-04T20:47:12Z","updated_at":"2026-07-22T22:24:38Z","subjects":["clouds","datacenters","abuse","misuse","resources","cryptocurrency","attacks","defense","anomaly-detection","reputation system","virtual machine communities"],"languages":["en"],"rights":["Copyright 2018 Rashid Tahir"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/101310","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Caesar, Matthew","Gunter, Carl","Borisov, Nikita","Zaffar, Fareed"]},{"key":"dc:creator","label":"Author","values":["Tahir, Rashid"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2018-09-04T20:47:12Z","2020-09-05T09:15:26Z","2018-04-13","2018-05"]},{"key":"dc:type","label":"Dc Type","values":["text"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Dissertation"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Ph.D."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["clouds","datacenters","abuse","misuse","resources","cryptocurrency","attacks","defense","anomaly-detection","reputation system","virtual machine communities"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2018 Rashid Tahir"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/101310"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Modern day commercial clouds are subject to various forms of infrastructural abuse. Whether it is SaaS, PaaS or IaaS model, attackers and cybercriminals are exploiting clouds to service their needs and using them as a platform to launch attacks and conduct illegal practices. Resultantly, instances where clouds are the source of a malicious or damaging activity have recently spiked. Unlike externally-sourced attacks on clouds, abuse arising from 'within' presents new challenges. This thesis highlights the emerging problem of cloud abuse and attempts to address these challenges. In particular, we argue for a new approach to cloud security that mitigates abuse proactively before the damage is done. Current defense mechanisms are ill-suited as they are primarily designed to mitigate incoming attacks, where the cloud is the target of the attack. Outbound traffic and resource usage is seldom scrutinized for malicious and illegal activities. Furthermore, in-VM security software, such as anti-viruses and intrusion detection systems fail to provide adequate protection as they can be bypassed (using polymorphism, stealth etc.), hidden from (as in virtualization-aware rootkits) or altogether turned off (by getting root access). To make matters worse, hackers have invented automated mechanisms that exploit the freemium business model, allowing them to engineer large pools of resources by combining together the free tier supply. Potentially infinite storage banks and cryptocurrency mining farms with huge distributed footprints have been exposed on top of complimentary services offered by various Cloud Service Providers (CSPs). This has incentivized hackers further, as they can launch lucrative attacks, such as DDoS attacks and spamming, free of cost. Providers struggle to detect this abuse as they lack the necessary tools and infrastructure for proactive detection and mitigation. Currently, all parties (users and providers) are made aware of the abuse when the damage has already been done and different losses have been incurred either by the user or, as in most cases, the provider. These issues highlight the need for new security mechanisms specifically designed to target attacks originating from within the cloud. Hence, in this thesis, we present the design and implementation of an infrastructure that can prove to be useful in proactively thwarting a diverse range of cloud abuse. From break-ins and cryptocurrency mining to DDoS attacks and covert/side channels, the presented infrastructure has the potential to mitigate malicious activity across the spectrum with high accuracy and low overheads without compromising scalability or modularity. We argue that clouds need systems that can react to various forms of abuse by deploying VM-oblivious defenses and minimize co-residency between tenants by making deployments more mobile. Specifically, we present the design of monitors leveraging the lower layers of the cloud-stack, such as the hardware and hypervisor. Furthermore, we also provide meaningful strategies to dynamically reposition entire deployments to minimize the sharing of infrastructure between co-resident tenants. The systems discussed herein add to the security toolbox available to providers and assist them in detecting and mitigating resource abuse in its early stages.","Submission published under a 24 month embargo labeled 'Closed Access', the embargo will last until 2020-05-01","The student, Rashid Tahir, accepted the attached license on 2018-04-12 at 21:42.","The student, Rashid Tahir, submitted this Dissertation for approval on 2018-04-12 at 23:56.","This Dissertation was approved for publication on 2018-04-13 at 14:45.","DSpace SAF Submission Ingestion Package generated from Vireo submission #12225 on 2018-08-31 at 17:28:48","Made available in DSpace on 2018-09-04T20:47:12Z (GMT). No. of bitstreams: 2 TAHIR-DISSERTATION-2018.pdf: 6399509 bytes, checksum: e0ab4a9072fbd5ad4d7c5a2168ff7e50 (MD5) LICENSE.txt: 4209 bytes, checksum: 502a600fabc1e8ed05108e0a9ef303c1 (MD5) Previous issue date: 2018-04-13","Embargo set by: Seth Robbins for item 107395 Lift date: 2020-09-04T20:47:38Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","Embargo set by: Seth Robbins for item 107395 Lift date: 2020-09-04T20:50:11Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","Limited Restriction Lifted for Item 107395 on 2020-09-05T09:15:26Z."]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Proactive abuse prevention in clouds"]}]}],"canonical_facts":{"dc:contributor":["Caesar, Matthew","Gunter, Carl","Borisov, Nikita","Zaffar, Fareed"],"dc:creator":["Tahir, Rashid"],"dc:date":["2018-09-04T20:47:12Z","2020-09-05T09:15:26Z","2018-04-13","2018-05"],"dc:description":["Modern day commercial clouds are subject to various forms of infrastructural abuse. Whether it is SaaS, PaaS or IaaS model, attackers and cybercriminals are exploiting clouds to service their needs and using them as a platform to launch attacks and conduct illegal practices. Resultantly, instances where clouds are the source of a malicious or damaging activity have recently spiked. Unlike externally-sourced attacks on clouds, abuse arising from 'within' presents new challenges. This thesis highlights the emerging problem of cloud abuse and attempts to address these challenges. In particular, we argue for a new approach to cloud security that mitigates abuse proactively before the damage is done. Current defense mechanisms are ill-suited as they are primarily designed to mitigate incoming attacks, where the cloud is the target of the attack. Outbound traffic and resource usage is seldom scrutinized for malicious and illegal activities. Furthermore, in-VM security software, such as anti-viruses and intrusion detection systems fail to provide adequate protection as they can be bypassed (using polymorphism, stealth etc.), hidden from (as in virtualization-aware rootkits) or altogether turned off (by getting root access). To make matters worse, hackers have invented automated mechanisms that exploit the freemium business model, allowing them to engineer large pools of resources by combining together the free tier supply. Potentially infinite storage banks and cryptocurrency mining farms with huge distributed footprints have been exposed on top of complimentary services offered by various Cloud Service Providers (CSPs). This has incentivized hackers further, as they can launch lucrative attacks, such as DDoS attacks and spamming, free of cost. Providers struggle to detect this abuse as they lack the necessary tools and infrastructure for proactive detection and mitigation. Currently, all parties (users and providers) are made aware of the abuse when the damage has already been done and different losses have been incurred either by the user or, as in most cases, the provider. These issues highlight the need for new security mechanisms specifically designed to target attacks originating from within the cloud. Hence, in this thesis, we present the design and implementation of an infrastructure that can prove to be useful in proactively thwarting a diverse range of cloud abuse. From break-ins and cryptocurrency mining to DDoS attacks and covert/side channels, the presented infrastructure has the potential to mitigate malicious activity across the spectrum with high accuracy and low overheads without compromising scalability or modularity. We argue that clouds need systems that can react to various forms of abuse by deploying VM-oblivious defenses and minimize co-residency between tenants by making deployments more mobile. Specifically, we present the design of monitors leveraging the lower layers of the cloud-stack, such as the hardware and hypervisor. Furthermore, we also provide meaningful strategies to dynamically reposition entire deployments to minimize the sharing of infrastructure between co-resident tenants. The systems discussed herein add to the security toolbox available to providers and assist them in detecting and mitigating resource abuse in its early stages.","Submission published under a 24 month embargo labeled 'Closed Access', the embargo will last until 2020-05-01","The student, Rashid Tahir, accepted the attached license on 2018-04-12 at 21:42.","The student, Rashid Tahir, submitted this Dissertation for approval on 2018-04-12 at 23:56.","This Dissertation was approved for publication on 2018-04-13 at 14:45.","DSpace SAF Submission Ingestion Package generated from Vireo submission #12225 on 2018-08-31 at 17:28:48","Made available in DSpace on 2018-09-04T20:47:12Z (GMT). No. of bitstreams: 2 TAHIR-DISSERTATION-2018.pdf: 6399509 bytes, checksum: e0ab4a9072fbd5ad4d7c5a2168ff7e50 (MD5) LICENSE.txt: 4209 bytes, checksum: 502a600fabc1e8ed05108e0a9ef303c1 (MD5) Previous issue date: 2018-04-13","Embargo set by: Seth Robbins for item 107395 Lift date: 2020-09-04T20:47:38Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","Embargo set by: Seth Robbins for item 107395 Lift date: 2020-09-04T20:50:11Z Reason: Author requested closed access (OA after 2yrs) in Vireo ETD system","Limited Restriction Lifted for Item 107395 on 2020-09-05T09:15:26Z."],"dc:format":["application/pdf"],"dc:identifier":["http://hdl.handle.net/2142/101310"],"dc:language":["en"],"dc:rights":["Copyright 2018 Rashid Tahir"],"dc:subject":["clouds","datacenters","abuse","misuse","resources","cryptocurrency","attacks","defense","anomaly-detection","reputation system","virtual machine communities"],"dc:title":["Proactive abuse prevention in clouds"],"dc:type":["text"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Dissertation"],"thesis:degree_name":["Ph.D."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:24:38Z"}