Hybrid Supervised Machine Learning Driven Novel IP Reputation Validating Techniques for Cloud Firewalls

NW Chanaka Lasantha, MWP Maduranga, Ruvan Abeysekara · 2024

Cloud firewall systems have exponentially improved with artificial intelligence (AI) to achieve more accurate IP Reputation (IPR) validation and robust threat detection. In this paper, we present a novel hybrid Machine Learning (ML) approach to infer IP address reputation to protect hosted applications in Amazon Web Services (AWS) cloud infrastructure. A multi-source data pipeline, including Security Operation Centres (SOC) logs, WAF and Guard Duty Logs, is leveraged to have higher precision and better utility in the IP reputation assessment. This solution takes pre-processed IP threat metadata as input and passes it through an ensemble ML model of Random Forest (RF), Linear Regression (LR), and Support Vector Machine (SVM) classifiers. Different aspects of IP threat detection are addressed by each algorithm. This hybrid model tracks suspicious IP patterns, aggregates findings for supervisory analysis, and dynamically creates AWS Firewall rules to block identified threats in real time. The system learns to synchronously adapt to changing ensemble models’ output through the IP-List and Instant Blacklists, significantly improving their overall defence capability. It achieves substantial reduction of false positives and fasten the response to combat against malicious IP behaviour in cloud hosted applications and is quite secure and robust.

Read the paper · More papers on PaperTik