ML-BASED DETECTION AND PREVENTION OF PRIVILEGE ESCALATION ATTACKS IN CLOUD ENVIRONMENTS
P Manjulatha, Yaswanth Sai, G Rakshit Kumar, Krishna Prasad, M Shiva Prasad · Journal of Science Engineering Technology and Management Sciences · 2025
Cloud computing has transformed how businesses and individuals store and access data, but it has also introduced critical vulnerabilities-particularly insider threats.These threats arise when employees or privileged users misuse their access to sensitive information.According to the 2022 Cloud Security Report, insider attacks account for approximately 35% of all global cloud data breaches.Detecting such threats in cloud environments is vital to maintaining data integrity, confidentiality, and business continuity.Traditional detection methods-such as rule-based systems, manual audits, and access log analyses-are reactive, time-consuming, and prone to human error.These conventional systems are often ineffective in large-scale cloud infrastructures, where the volume of data is immense and rapidly changing, making timely threat detection difficult.Given the rising frequency of insider threat incidents and the limitations of existing methods, there is a growing need for more advanced and automated solutions.Machine learning, especially ensemble learning models, provides a promising approach to enhancing detection capabilities.By leveraging algorithms like Random Forest, AdaBoost, and CatBoost, these models can efficiently analyze user behavior patterns, identify anomalies, and detect potential threats in real-time.Unlike traditional systems, machine learning models can process vast datasets from cloud logs and user activities more accurately, reducing false positives and significantly improving the effectiveness of security responses.