ThreatPro: Multi-Layer Threat Analysis in the Cloud
Salman Manzoor, Antonios Gouglidis, Matthew Bradbury, Neeraj, Suri

TL;DR
ThreatPro is a novel multi-layer threat analysis framework designed for dynamic Cloud environments, enabling detailed attack behavior exploration and security assessment across complex, multi-layered systems.
Contribution
It introduces a technology-agnostic flow model for analyzing multi-layer and dynamic threats in Cloud systems, addressing limitations of existing static analysis techniques.
Findings
Successfully identified and traced real Cloud attacks.
Able to postulate potential attack paths.
Validated using public threat data from NVD.
Abstract
Many effective Threat Analysis (TA) techniques exist that focus on analyzing threats to targeted assets (e.g., components, services). These techniques consider static interconnections among the assets. However, in dynamic environments, such as the Cloud, resources can instantiate, migrate across physical hosts, or decommission to provide rapid resource elasticity to the users. It is evident that existing TA techniques cannot address all these requirements. In addition, there is an increasing number of complex multi-layer/multi-asset attacks on Cloud systems, such as the Equifax data breach. Hence, there is a need for threat analysis approaches that are designed to analyze threats in complex, dynamic, and multi-layer Cloud environments. In this paper, we propose ThreatPro that addresses the analysis of multi-layer attacks and supports dynamic interconnections in the Cloud. ThreatPro…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Security and Intrusion Detection · Information and Cyber Security · Software System Performance and Reliability
