返回
Domain knowledge free cloud-IDS with lightweight embedding method
DOI:10.1186/s13677-024-00707-8.png)
摘要
En 中文
The expansion of the cloud computing market has provided a breakthrough in efficiently storing and managing data for individuals and companies. As personal and corporate data move to the cloud, diverse attacks targeting the cloud have also increased for heist beneficial information. Therefore, cloud service providers offer protective environments through diverse security solutions. However, security solutions are limited in preventing advanced attacks because it is challenging to reflect the environment of each user. This paper proposes a Cloud Intrusion Detection System (C-IDS) that adapts to each user's cloud environment and performs real-time attack detection using Natural Language Processing (NLP). Notably, the C-IDS learns the deployed client environment logs and detects anomalies using the Seq2Seq model with BI-LSTM and Bahdanau attention. We used multiple domain datasets, Linux, Windows, Hadoop, OpenStack, Apache, OpenSSH, and CICIDS2018 to verify the performance of the C-IDS. C-IDS consists of a 'recognition' that identifies logs in the deployed environment and a 'detection' that discovers anomalies. The recognition results showed an average accuracy of 98.2% for multiple domain datasets. Moreover, the detection results based on the trained model exhibited an average accuracy of 94.2% for the Hadoop, OpenStack, Apache, and CICIDS2018 datasets.
Keyword:
Cloud computing
Cyber security
Natural language processing
Intrusion detection system
Anomaly detection
CICIDS-2018 dataset
System log analysis
期刊
J
IF:
4.3
论文数:
746
被引数:
2.2K
机构
引用论文
An Improved Design for a Cloud Intrusion Detection System Using Hybrid Features Selection Approach With ML Classifier使用混合特征选择方法和ML分类器的云入侵检测系统的改进设计
IEEE ACCESS
IF3.6
LogEvent2vec: LogEvent-to-Vector Based Anomaly Detection for Large-Scale Logs in Internet of Things
SENSORS
IF3.5

