An improved anomaly detection model for classification of underrepresented malware in the cloud
Open Access DepositedThe proliferation of cloud computing has coincided with an increase in sophisticated cyberattacks, particularly those leveraging encrypted traffic to evade detection. This research addresses the critical challenge of detecting and classifying malware within encrypted cloud network traffic, with a specific focus on underrepresented malware types. This research proposes a novel deep learning-based anomaly detection system that builds upon previous work by L.P. Khan et al. (2022). The approach significantly improves the detection accuracy for underrepresented malware variants within a diverse set of over twenty different malware types. Utilizing the NF-UQ-NIDS-v2 dataset, comprising over 75 million simulated and real-world NetFlow records, this research identifies key features for differentiating malicious from benign traffic. The analysis reveals that the Layer 7 Protocol and the Longest Packet Flow are the most informative features for this classification task. Through comprehensive experimentation with various deep learning architectures, the research concludes that a four-hidden-layer neural network provides optimal performance for detecting and classifying intrusions, particularly for underrepresented malware data. The model achieves a precision accuracy exceeding 95% across multiple malware categories. This research advances the field of cloud security by showcasing the effectiveness of integrating multiple deep-learning models to improve malware detection. The proposed system offers a robust solution for identifying both common and rare malware types in encrypted cloud traffic, addressing a significant gap in current intrusion detection capabilities.
- All rights reserved
Notice to Authors
If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.