ANOMALY DETECTION IN DOCKER CONTAINERS WITH LSTM AND DECISION TREES
International Research Journal of Modernization in Engineering Technology and Science · 2025
The containerized applications have completely changed the battle of cloud computing by providing the facility of lightweight, scalable, and efficient microservice deployment.Indeed, as their adoption increases, so do the security vulnerabilities associated with them, and intrusion detection is a serious issue.Still, modern intrusion detection systems (IDS) are usually weak at handling dynamic characteristics of Docker environments and so end up highly exposed to the latest cyber threats.This research proposes an AI-driven approach to improve the intrusion detection on Docker containers.We developed a model that can identify the anomalous behaviour in real-time with the help of Long Short Term Memory (LSTM) networks and Decision Tree algorithms.Finally, we implement a Falco integration with the ELK Stack for complete monitoring, logging, and alerting.With an experimental evaluation, good results were obtained with a detection accuracy of 98.13%, which outperforms conventional IDS solutions.This work makes key contributions in the development of a lightweight and highspeed anomaly detection framework designed for Docker environment assessment, a benchmark comparison of state-of-the-art AI and traditional IDS against each other, and a real-time alerting system that improves security operations.The results show how AI-based IDS not only improves detection accuracy but also reduces false positives, which makes the system for the protection of containerized applications against evolving cyber threats.