FlexIPAccess: Dynamic Attribute based IP analysis using Machine Learning Approach
Rajeev K. Singh, Pradeepta Mishra, Shinu Abhi · 2024
With the rapid growth of cloud service adoption, ensuring efficient IP access control and reputation verification has become a critical concern. Cybersecurity engineers are currently facing complexities in managing numerous security tools simultaneously. One significant challenge is the time-intensive nature of security provider analysis tools, which can take days or even a week to provide information about IP. The FlexIPAccess is introduced as a machine learning-based solution that targets the urgent cybersecurity challenges faced in Information Technology (IT) operations. When acquiring IPs for public service hosting, it’s crucial to consider potential blacklisting to prevent unintentional acquisition of problematic IPs. Instances have occurred where a single IP serves multiple public applications, allowing cyber attackers to camouflage their malicious activities. This research prioritizes the detection of malicious activity through the analysis of IP patterns, historical data, network reachability, and geolocation. These factors are applied in a machine learning model for data processing and classification. Cloud-based IP providers like Azure, Amazon Web Services (AWS), Ali Cloud, and Google Cloud Platform (GCP). Cloud providers utilize IP from various sources, making it difficult to verify authenticity and concurrent usage by other applications. The FlexIPAccess leverages key security platforms such as VirusTotal, AbuseIP, PhishingTank, AlienVault, and WHOIS Database for IP to gather essential insights, including IP addresses, Domain Name System (DNS), WHOIS records, Uniform Resource Locator (URL), and domains. In the proposed work, malicious IPs are detected from network logs. The dataset has been categorized into two types: Normal and Attack, with a total of 183,139 IPs used for the implementation. Three machine learning algorithms—Random Forest, Decision Tree, and Logistic Regression—were implemented to detect and classify the malicious IPs.