Cloud Anomaly Detection Strategy with a Hybrid Approach: Evaluation and Future Improvements
Akram Lichani, Radouane Nouara, Nabil Belala · 2024
The increasing volume of data and the complexity of network traffic have created a significant challenge for enterprises. They must ensure the integrity of their data stored in the cloud. For this they require the use of systems for anomaly detection to protect digital infrastructures. In this paper, we examine the CICIDS2017 dataset, a comprehensive benchmark for evaluating anomaly detection methods, which includes various network attacks and benign traffic. We propose a comprehensive methodology that integrates dimensionality reduction using an autoencoder anomaly detection that uses the Isolation Forest, and supervised classification with XGBoost. The approach tackles the issue of class imbalances present in the dataset by using the SMOTE strategy, thereby improving the model's capacity to identify rare assaults. We evaluate our model's effectiveness through comprehensive experiments, achieving high precision to distinguish legitimate and malicious communications. Visual representations and descriptive statistics illustrate the dataset imbalance and the efficacy of our methodology in practical applications. The results demonstrate that our hybrid approach effectively maintains a high detection rate while reducing false positives, providing a reliable solution for cloud computing security.