Zero-SAD: Zero-Shot Learning Using Synthetic Abnormal Data for Abnormal Behavior Detection on Private Cloud
Jae-Seok Kim, Joonho Seo, Seon-Jin Hwang, Jinmyeong Shin, Yoon-Ho Choi · 2024
While many studies have been conducted to detect abnormal behavior in cloud environments by analyzing system call sequences, these studies often cannot be applied to real-world cloud environments since they do not consider actual user behavior and rely on publicly available datasets. In actual cloud environments, the frequency of duplicate system calls is significantly higher than that observed in these datasets. This discrepancy necessitates a considerably larger scale of analysis to fully understand the sequential relationships among system calls. In this paper, we propose a practical abnormal behavior detection system for private cloud environments. The proposed system comprises of a deduplicated embedding process that efficiently represents duplicate system calls occurring within the cloud into a single embedding vector and a zero-shot abnormal behavior detection process that rapidly analyzes the large volume of system call sequences generated by numerous users through a zero-shot learning model. To demonstrate the practicality of our proposed system, we use both publicly available datasets and datasets directly collected from real cloud environments by implementing attacks from the MITRE ATT&CK framework as a proof of concept (PoC). Experimental results show that our system achieved an accuracy an accuracy of 92.13%, and it can detect attacks 5.48 times faster than existing research.