Machine learning for cloud-based privilege escalation attack detection and mitigation with CATBOOST
Abstract
Because of the emergence of smart gadgets, cyber security has become a serious worry owing to the exponential rise in attack frequency with complexity in recent years. Cloud computing has revolutionised business, but its centralization makes distributed services like security systems more difficult to use. Due to the volume of data exchanged between businesses and cloud service providers, there is a considerable danger of malicious or inadvertent exposure of critical information. A hostile insider is a very dangerous person for the firm since they have more access and possibilities to do significant damage. Data and assets that are not available to people on the outside are exclusively and authorised accessible to those within. This study describes an approach based on machine learning for categorising insider threats and detecting anomalous occurrences that can point to security problems associated with privilege escalation. To identify these abnormalities, the system employs a methodical methodology. Ensemble learning takes numerous models into account and improves both prediction performance and machine learning outcomes. Finding security flaws or risks related to the delegation of privileges in network systems using anomaly and vulnerability detection has been the subject of several studies. But these studies do not provide a precise identification of the attacks. This study proposes and evaluates machine learning (ML) ensembles. The goal of this effort is to use machine learning techniques to categorise insider attacks. It makes use of a dataset the fact that has been customised from a lot of files the inside the CERT dataset. Four machine learning techniques (Light GBM, XG Boost, Ada boost, three Random Forest (RF)) are applied to the dataset. Light had the best overall performance. Conversely, two algorithms that could be more effective in thwarting internal attacks (such behavioural biometrics attacks) are RF and AdaBoost. Therefore, integrating several machine learning methods might lead to a better classification in different internal attacks. The Light GBM approach performs better than the other recommended algorithms, with a reliability of 97%; RF is 86% accurate, AdaBoost is 88% accurate, and XG Boost is 88.27% accurate.
How this paper connects to the literature. Drag to explore, click any node to open that paper.
