The document discusses the NICE (Network Intrusion detection and Countermeasure sElection in virtual network systems) framework. NICE aims to establish a defense-in-depth intrusion detection system for virtual network systems. It incorporates attack graph analysis to improve attack detection. NICE employs a reconfigurable virtual networking approach to detect attacks attempting to compromise VMs and prevent them from being used as "zombie VMs". It models security threats using attack graphs and scenario attack graphs. NICE also proposes a VM protection model using a VM profiler, security indexer, and state monitor to protect VMs based on their security index and connectivity.