Generation of a dataset for DoW attack detection in serverless architectures.
José Manuel Ortega Candel1, Francisco José Mora Gimeno1, Higinio Mora Mora1
1Department of Computer Science and Technology, Alicante University, Alicante, Spain.
Data in Brief
|December 14, 2023
Summary
This study introduces a new dataset to help detect Denial of Wallet (DoW) attacks in serverless computing. The dataset aids in developing machine learning models for identifying these costly cyber threats.
Area of Science:
- Cloud Computing Security
- Cybersecurity
- Data Science
Background:
- Denial of Wallet (DoW) attacks exploit serverless environments, causing excessive costs.
- Serverless architectures (Function-as-a-Service) offer scalability but are vulnerable to DoW attacks.
- A lack of realistic datasets hinders research into DoW attack detection.
Purpose of the Study:
- To create a synthetic dataset for simulating function invocations in serverless architectures.
- To facilitate the development and evaluation of machine learning models for DoW attack detection.
- To provide a valuable resource for researchers and developers in serverless security.
Main Methods:
- Generated synthetic data based on real cloud traffic patterns.
- Identified key characteristics of function invocations: SubmitTime, Invocation Delay, Response Delay, Function Duration, Active Functions at Request, and Active Functions at Response.
- Proposed a methodology for dataset generation and its application in attack detection.
Main Results:
- A novel dataset simulating serverless function invocations has been created.
- The dataset captures essential characteristics for analyzing serverless traffic.
- The dataset is available in the Mendeley data repository for public use.
Conclusions:
- The generated dataset is crucial for advancing research in Denial of Wallet attack detection in serverless environments.
- Machine learning techniques and neural networks can be effectively applied using this dataset.
- This resource will enhance the reliability, efficiency, and security of serverless applications.
Related Concept Videos
Wald-Wolfowitz Runs Test I
651
The Wald-Wolfowitz test, also known as the runs test, is a nonparametric statistical test used to assess the randomness of a sequence of two different types of elements (e.g., positive/negative values, successes/failures). It examines whether the order of the elements in a sequence is random or if there is a pattern or trend present. This nonparametric test applies to any ordered data despite the population and sample data distribution, even if a higher sample size is available.
The test works...
The test works...
651
Wald-Wolfowitz Runs Test II
244
The Wald-Wolfowitz runs test, commonly referred to as the runs test, is a nonparametric test used to assess the randomness of ordered data. The test evaluates the number of runs, which are consecutive sequences of similar elements within the data. If the number of runs is significantly higher or lower than expected, the data is considered non-random, indicating a detectable pattern or structure.
For binary data, runs are identified using symbols such as + and −, or equivalently, 1s and...
For binary data, runs are identified using symbols such as + and −, or equivalently, 1s and...
244
Mass Analyzers: Overview
683
The mass analyzer is a crucial component of the mass spectrometer. In the ionization chamber, the vaporized sample is bombarded with a high-energy electron beam to generate a radical cation and further fragment into neutral molecules, radicals, and cations. A series of negatively charged accelerator plates accelerate the cations into the mass analyzer. The mass analyzer separates ions according to their mass-to-charge (m/z) ratios and then directs them to the detector. The common types of mass...
683
Cluster Sampling Method
11.9K
Appropriate sampling methods ensure that samples are drawn without bias and accurately represent the population. Because measuring the entire population in a study is not practical, researchers use samples to represent the population of interest.
To choose a cluster sample, divide the population into clusters (groups) and then randomly select some of the clusters. All the members from these clusters are in the cluster sample. For example, if you randomly sample four departments from your...
To choose a cluster sample, divide the population into clusters (groups) and then randomly select some of the clusters. All the members from these clusters are in the cluster sample. For example, if you randomly sample four departments from your...
11.9K
Distribution Reliability and Automation
108
Distribution reliability in electrical power systems is critical for ensuring an uninterrupted power supply to consumers at minimal cost. According to IEEE Standard Terms, reliability is the probability that a device will function without failure over a specified time period or amount of usage. For electric power distribution, this translates to maintaining continuous power supply and addressing customer concerns over power outages. Several indices, as defined by IEEE Standard 1366-2012, are...
108
Difference from Background: Limit of Detection
6.4K
The limit of detection (LOD) is the smallest amount of analyte that can be distinguished from the background noise. The LOD value corresponds to the concentration at which the analyte signal is three times larger than the standard deviation of the blank signal. Below this value, the analyte signal cannot be differentiated from the background noise. It is calculated by dividing the calibration slope by 3 times the standard deviation of the blank signals.
The LOD indicates the presence or absence...
The LOD indicates the presence or absence...
6.4K


