Multi-Class Threat Detection Using Neural Network and Machine Learning Approaches in Kubernetes Environments
Abdelrahman Aly, Mahmoud Fayez, Mirvat Al-Qutt, Ahmed Mahmoud Hamad · 2024
Kubernetes, an open-source platform for automating deployment, scaling, and management of containerized applications, has become a cornerstone in modern IT infrastructure. Alongside its widespread adoption, Kubernetes faces a series of sophisticated security challenges, especially in managing numerous containers. This research uniquely focuses on multi-class threat detection, classifying various types of security threats within Kubernetes environments. Machine learning is emerging as a powerful tool in cybersecurity, offering new ways to detect and mitigate threats. However, there is a shortage of comprehensive research on its application within Kubernetes, especially for detecting multiple types of security threats. This research aims to bridge this gap by introducing a machine learning-based technique for improved threat detection in Kubernetes environments. We propose an advanced detection method using the Naive Bayes algorithm, complemented by comprehensive feature engineering and dimensionality reduction using neural networks. The most effective model, which combines Principal Component Analysis (PCA) and Autoencoder with the Naive Bayes classifier, achieved an F1 Score of 0.95 and an accuracy of 91%.