Privilege Escalation Attack Detection and Mitigation in Cloud Using Machine Learning

被引:14
|
作者
Mehmood, Muhammad [1 ]
Amin, Rashid [1 ,2 ]
Muslam, Muhana Magboul Ali [3 ]
Xie, Jiang [4 ]
Aldabbas, Hamza [5 ]
机构
[1] Univ Engn & Technol Taxila, Dept Comp Sci, Taxila 47050, Pakistan
[2] Univ Chakwal, Dept Comp Sci, Chakwal 48800, Pakistan
[3] Imam Mohammad Ibn Saud Islamic Univ, Dept Informat Technol, Riyadh 11432, Saudi Arabia
[4] Univ North Carolina Charlotte UNC Charlotte, Dept Elect & Comp Engn, Charlotte, NC 28223 USA
[5] Al Balqa Appl Univ, Prince Abdullah bin Ghazi Fac Informat & Commun Te, Al Salt 1705, Jordan
关键词
Security; Machine learning algorithms; Cloud computing; Classification algorithms; Random forests; Machine learning; Data models; Privilege escalation; insider attack; machine learning; random forest; adaboost; XGBoost; LightGBM; classification; INSIDER THREAT DETECTION; SYSTEM;
D O I
10.1109/ACCESS.2023.3273895
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Because of the recent exponential rise in attack frequency and sophistication, the proliferation of smart things has created significant cybersecurity challenges. Even though the tremendous changes cloud computing has brought to the business world, its centralization makes it challenging to use distributed services like security systems. Valuable data breaches might occur due to the high volume of data that moves between businesses and cloud service suppliers, both accidental and malicious. The malicious insider becomes a crucial threat to the organization since they have more access and opportunity to produce significant damage. Unlike outsiders, insiders possess privileged and proper access to information and resources. In this work, a machine learning-based system for insider threat detection and classification is proposed and developed a systematic approach to identify various anomalous occurrences that may point to anomalies and security problems associated with privilege escalation. By combining many models, ensemble learning enhances machine learning outcomes and enables greater prediction performance. Multiple studies have been presented regarding detecting irregularities and vulnerabilities in network systems to find security flaws or threats involving privilege escalation. But these studies lack the proper identification of the attacks. This study proposes and evaluates ensembles of Machine learning (ML) techniques in this context. This paper implements machine learning algorithms for the classification of insider attacks. A customized dataset from multiple files of the CERT dataset is used. Four machine learning algorithms, i.e., Random Forest (RF), Adaboost, XGBoost, and LightGBM, are applied to that dataset and analyzed results. Overall, LightGBM performed best. However, some other algorithms, such as RF or AdaBoost, may perform better on some internal attacks (Behavioral Biometrics attacks) or other internal attacks. Therefore, there is room for incorporating more than one machine learning algorithm to obtain a stronger classification in multiple internal attacks. Among the proposed algorithms, the LightGBM algorithm provides the highest accuracy of 97%; the other accuracy values are RF at 86%, AdaBoost at 88%, and XGBoost at 88.27%.
引用
收藏
页码:46561 / 46576
页数:16
相关论文
共 50 条
  • [21] Phishing attack detection using Machine Learning
    Pandiyan S S.
    Selvaraj P.
    Burugari V.K.
    Benadit P J.
    P K.
    Measurement: Sensors, 2022, 24
  • [22] Novel Class Probability Features for Optimizing Network Attack Detection With Machine Learning
    Raza, Ali
    Munir, Kashif
    Almutairi, Mubarak S.
    Sehar, Rukhshanda
    IEEE ACCESS, 2023, 11 : 98685 - 98694
  • [23] A Survey on Attack Detection Methods For IOT Using Machine Learning And Deep Learning
    Babu, Meenigi Ramesh
    Veena, K. N.
    ICSPC'21: 2021 3RD INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING AND COMMUNICATION (ICPSC), 2021, : 625 - 630
  • [24] A DDoS Attack Mitigation Scheme in ISP Networks Using Machine Learning Based on SDN
    Nguyen Ngoc Tuan
    Pham Huy Hung
    Nguyen Danh Nghia
    Nguyen Van Tho
    Trung Van Phan
    Nguyen Huu Thanh
    ELECTRONICS, 2020, 9 (03)
  • [25] Guarding the Cloud: An Effective Detection of Cloud-Based Cyber Attacks using Machine Learning Algorithms
    Rexha, Blerim
    Thaqi, Rrezearta
    Mazrekaj, Artan
    Vishi, Kamer
    INTERNATIONAL JOURNAL OF ONLINE AND BIOMEDICAL ENGINEERING, 2023, 19 (18) : 158 - 174
  • [26] Detection of DDoS Attacks Using Machine Learning in Cloud Computing
    Sharma, Vishal
    Verma, Vinay
    Sharma, Anand
    ADVANCED INFORMATICS FOR COMPUTING RESEARCH, ICAICR 2019, PT II, 2019, 1076 : 260 - 273
  • [27] Malicious attack detection approach in cloud computing using machine learning techniques
    M. Arunkumar
    K. Ashok Kumar
    Soft Computing, 2022, 26 : 13097 - 13107
  • [28] Ransomware Attack Detection on the Internet of Things Using Machine Learning Algorithm
    Zewdie, Temechu Girma
    Girma, Anteneh
    Cotae, Paul
    HCI INTERNATIONAL 2022 - LATE BREAKING PAPERS: INTERACTING WITH EXTENDED REALITY AND ARTIFICIAL INTELLIGENCE, 2022, 13518 : 598 - 613
  • [29] Homoglyph Attack Detection Model Using Machine Learning and Hash Function
    Almuhaideb, Abdullah M.
    Aslam, Nida
    Alabdullatif, Almaha
    Altamimi, Sarah
    Alothman, Shooq
    Alhussain, Amnah
    Aldosari, Waad
    Alsunaidi, Shikah J.
    Alissa, Khalid A.
    JOURNAL OF SENSOR AND ACTUATOR NETWORKS, 2022, 11 (03)
  • [30] A Lightweight Model for DDoS Attack Detection Using Machine Learning Techniques
    Sadhwani, Sapna
    Manibalan, Baranidharan
    Muthalagu, Raja
    Pawar, Pranav
    APPLIED SCIENCES-BASEL, 2023, 13 (17):