VIETNAM NATIONAL UNIVERSITY HO CHI MINH CITY HO CHI MINH CITY UNIVERSITY OF TECHNOLOGY TRAN DANG TRI ENHANCING CLOUD INFRASTRUCTURE SECURITY THROUGH ANOMALY DETECTION WITH MACHINE LEARNING Major: Computer Science Major code: 8480101 MASTER’S THESIS HO CHI MINH CITY, June 2024 THIS THESIS IS COMPLETED AT HO CHI MINH CITY UNIVERSITY OF TECHNOLOGY – VNU-HCM Supervisor: Dr. Truong Tuan Anh Examiner 1: Assoc. Nguyen Tuan Dang Examiner 2: Dr. Ton Long Phuoc This master’s thesis is defended at HCM City University of Technology, VNU- HCM City on Jun 19, 2024 Master’s Thesis Committee: 1.
Tran Minh Quang 2. Nguyen Thi Ai Thao 3. Nguyen Tuan Dang 4. Ton Long Phuoc 5.
Truong Tuan Anh Approval of the Chair of Master’s Thesis Committee and Dean of Faculty of Computer Science after the thesis being corrected (If any). CHAIR OF THESIS COMMITTEE DEAN OF FACULTY OF COMPUTER SCIENCE AND ENGINEERING VIETNAM NATIONAL UNIVERSITY - HO CHI MINH CITY SOCIALIST REPUBLIC OF VIETNAM HO CHI MINH CITY UNIVERSITY OF TECHNOLOGY Independence – Freedom - Happiness THE TASK SHEET OF MASTER’S THESIS Full name: TRẦN ĐĂNG TRÍ Student ID: 2170458 Date of birth: 08/04/1985 Place of birth: Bien Hoa – Dong Nai Major: Computer Science Major ID: 8480101 I. THESIS TITLE: Enhancing cloud infrastructure security through anomaly detection with machine learning. Tăng cường bảo mật cho cơ sở hạ tầng đám mây thông qua việc phát hiện sự bất thường bằng công nghệ máy học.
TASKS AND CONTENTS: Conduct a comprehensive review of cloud security issues, emphasizing the limitations of traditional security measures within cloud infrastructure. Tiến hành đánh giá toàn diện các vấn đề bảo mật đám mây, nhấn mạnh những hạn chế của các biện pháp bảo mật truyền thống trong cơ sở hạ tầng đám mây. Evaluate both traditional and machine learning-based anomaly detection techniques to determine their suitability for cloud security. Đánh giá kỹ thuật phát hiện bất thường dựa trên máy học và truyền thống để xác định tính phù hợp của chúng đối với bảo mật đám mây.
Develop and implement a machine learning-based anomaly detection system tailored for cloud environments. Phát triển và triển khai hệ thống phát hiện bất thường dựa trên máy học được thiết kế riêng cho môi trường đám mây. Assess the effectiveness of the proposed anomaly detection system through rigorous experimentation and analysis. Đánh giá tính hiệu quả của hệ thống phát hiện sự bất thường được đề xuất thông qua thử nghiệm và phân tích nghiêm ngặt.
THESIS START DAY: 15/01/2024 IV. THESIS COMPLETION DAY: 20/05/2024 V. Truong Tuan Anh Ho Chi Minh City, May 19, 2024 SUPERVISOR CHAIR OF PROGRAM COMITTEE Dr. Truong Tuan Anh.
DEAN OF FACULTY OF COMPUTER SCIENCE AND ENGINEERING ACKNOWLEDGEMENT I extend my heartfelt gratitude to those whose unwavering support and encouragement have been pivotal in the completion of this master's thesis. My Thesis Supervisor I am deeply grateful to my thesis supervisor, Dr. Truong Tuan Anh, for his invaluable guidance, expertise, and steadfast support throughout this research endeavor. His insightful feedback, constructive criticism, and dedication to academic excellence have been the guiding lights that shaped the success of this thesis.
My Classmates in BK.2020 I want to express my sincere appreciation to my teammates and classmates who have generously shared their knowledge, insights, and experiences. The collaborative spirit and sense of community within our cohort have significantly enriched the depth and scope of this research. Special thanks to MSc. Ho Anh Thi, MSc.
Lai Trung Minh Duc. My beloved family To my beloved family, my wife and my kids, whose unwavering support and understanding have been the bedrock of my journey. Your encouragement, patience, and unwavering belief in my capabilities have been the motivating factors propelling me forward. I am eternally grateful for the sacrifices you have made to make this academic pursuit a reality.
Colleagues and Friends My heartfelt thanks to my (ex) colleagues and friends in McKinsey & Company, NFQ Asia, who have provided a supportive network, offering encouragement and camaraderie. The shared experiences and engaging discussions have broadened my perspective and made this academic pursuit more fulfilling. IMP Academic I appreciate the resources, facilities, and opportunities provided by IMP Academic. The team has played an indispensable role in shaping my research endeavors, and I am thankful for the intellectually stimulating environment that has nurtured my academic growth.
--- In conclusion, this thesis stands as a testament to collective effort, and I extend my deepest thanks to each person who has played a role, whether large or small, in its realization. Your support has been a priceless gift, and I am truly fortunate to be surrounded by such remarkable individuals. i ABSTRACT The rapid evolution and widespread adoption of cloud computing have brought unprecedented opportunities, but concurrently, have posed significant security challenges. Traditional security approaches, often static and rule-based, struggle to adapt to the dynamic and distributed nature of cloud environments.
This master's thesis addresses this gap by proposing and implementing an anomaly detection system to enhance security in cloud infrastructure using machine learning techniques. The research was inspired by a conversation between my supervisor, Dr. Truong Tuan Anh, a specialist and university lecturer focusing on CyberSecurity, and myself, a Technical Architect responsible for overseeing the cloud architecture for various projects in my company. We shared daily challenges in dealing with security matters in Cloud Architecture and applied machine learning in CyberSecurity.
This research begins with a comprehensive review of cloud security issues, emphasizing the limitations of existing security measures. It subsequently explores both traditional and machine learning-based anomaly detection techniques, highlighting the advantages of the latter in adapting to the evolving threat landscape of cloud computing. The methodology encompasses the selection and justification of machine learning algorithms tailored for cloud security, specifically Isolation Forests, Support Vector Machines (SVM) and Random Forest. The research also identifies key anomalous activities in cloud computing security, providing a foundation for the subsequent detection process.
Implementation involves the integration of the proposed anomaly detection system into cloud infrastructure, utilizing datasets representative of real-world cloud security scenarios. Challenges faced during implementation are addressed, and the system's architecture and dataset characteristics are detailed. For the scope of this research, I used AWS – Amazon Web Services, one of the most popular Cloud Service Providers in the world – to demonstrate. But the academic value of this research remains unchanged and easily applicable to other cloud services providers.
Results from the evaluation phase demonstrate the effectiveness of the proposed anomaly detection system, showcasing its ability to outperform baseline methods in identifying and mitigating security threats within the cloud environment. In conclusion, this master's thesis contributes to the field of cloud security by presenting a machine learning-based anomaly detection system applicable across diverse cloud service providers. The findings underscore the significance of proactive, adaptive security measures in safeguarding cloud infrastructure. ii TÓM TẮT LUẬN VĂN Sự phát triển nhanh chóng và việc áp dụng rộng rãi điện toán đám mây đã mang lại những cơ hội chưa từng có, nhưng đồng thời cũng đặt ra những thách thức an ninh đáng kể.
Các phương pháp bảo mật truyền thống, thường là tĩnh và dựa trên quy tắc, gặp khó khăn trong việc thích ứng với tính chất năng động và phân tán của môi trường đám mây. Luận văn thạc sĩ này cố gắng giải quyết thách thức này bằng cách đề xuất và triển khai một hệ thống phát hiện sự bất thường để tăng cường bảo mật trong cơ sở hạ tầng đám mây bằng cách sử dụng kỹ thuật học máy. Nghiên cứu này được lấy cảm hứng từ cuộc trò chuyện giữa giảng viên hướng dẫn của tôi, TS. Trương Tuấn Anh, một chuyên gia và giảng viên đại học chuyên về An ninh mạng, và tôi, một Kiến trúc sư kỹ thuật chịu trách nhiệm giám sát kiến trúc đám mây cho nhiều dự án khác nhau trong công ty mà tôi đang công tác.
Chúng tôi đã chia sẻ những thách thức hàng ngày trong việc xử lý các vấn đề bảo mật trong Kiến trúc đám mây và ứng dụng học máy trong An ninh mạng. Nghiên cứu này bắt đầu bằng việc xem xét toàn diện các vấn đề bảo mật đám mây, nhấn mạnh những hạn chế của các biện pháp bảo mật hiện có. Sau đó, nó khám phá cả kỹ thuật phát hiện bất thường dựa trên máy học và truyền thống, nêu bật những ưu điểm của kỹ thuật này trong việc thích ứng với bối cảnh mối đe dọa ngày càng gia tăng của điện toán đám mây. Phương pháp này bao gồm việc lựa chọn và chứng minh các thuật toán học máy phù hợp với bảo mật đám mây, cụ thể là Isolation Forests, Support Vector Machines (SVM) và Random Forest.
Nghiên cứu cũng xác định các hoạt động bất thường quan trọng trong bảo mật điện toán đám mây, cung cấp nền tảng cho quá trình phát hiện tiếp theo. Việc triển khai bao gồm việc tích hợp hệ thống phát hiện bất thường được đề xuất vào cơ sở hạ tầng đám mây, sử dụng bộ dữ liệu đại diện cho các kịch bản bảo mật đám mây trong thế giới thực. Những thách thức gặp phải trong quá trình triển khai được giải quyết và kiến trúc của hệ thống cũng như các đặc điểm tập dữ liệu được trình bày chi tiết. Trong phạm vi nghiên cứu này, tôi đã sử dụng AWS – Amazon Web Services, một trong những Nhà cung cấp dịch vụ đám mây phổ biến nhất hiện nay – để hiện thực hóa.
Nhưng giá trị học thuật của nghiên cứu này vẫn không thay đổi và dễ dàng áp dụng cho các nhà cung cấp dịch vụ đám mây khác. Kết quả từ giai đoạn đánh giá chứng minh tính hiệu quả của hệ thống phát hiện bất thường được đề xuất, cho thấy khả năng vượt trội hơn các phương pháp cơ bản trong việc xác định và giảm thiểu các mối đe dọa bảo mật trong môi trường đám mây. Tóm lại, luận án thạc sĩ này đóng góp cho lĩnh vực bảo mật đám mây bằng cách trình bày hệ thống phát hiện bất thường dựa trên máy học có thể áp dụng trên nhiều nhà cung cấp dịch vụ đám mây khác nhau. Những phát hiện này nhấn mạnh tầm quan trọng của các biện pháp bảo mật chủ động, thích ứng trong việc bảo vệ cơ sở hạ tầng đám mây.
iii DISCLAIMER I hereby declare that this master thesis is my own original work and has not been submitted before to any institution for assessment purposes. Further, I have acknowledged all sources used and have cited these in the reference section. May 2024 Tran Dang Tri Date iv TABLE OF CONTENTS Chapter 1. Overview of Cloud Computing.
Importance of Security in Cloud Infrastructure. Anomaly Detection in Cloud Security. Challenges in Traditional Security Approaches. Need for Machine Learning-Based Anomaly Detection.
Overall Goal of the Thesis. Specific Research Objectives. Potential Challenges and Promising Machine Learning Solutions. Scope and Limitations.
Scope of the Thesis. Limitations and Constraints. Overview of Cloud Security Issues. Existing Security Measures in Cloud Infrastructure.
Anomalous Activities in Cloud Computing Security. Traditional Anomaly Detection Techniques. Machine Learning-Based Approaches. Types of Data Sources.
Data Preprocessing Steps. Machine Learning Algorithms. Performance Metrics for Anomaly Detection. Overview of the Proposed System.
Integration with Cloud Infrastructure. Characteristics of the Dataset. Data Splitting for Training and Testing. Machines Learning Models Chosen.
Support Vector Machines (SVM). Coding Languages and Frameworks Used. Challenges Faced and Solutions. Comparison based on evaluation metrics.
Implications of the Study. Challenges and Limitations .