An Enhanced Model for Server-Side Attack Detection and Blocking in Cloud Computing Environment
Abstract
The rapid expansion of cloud computing has revolutionized IT infrastructure, offering significant benefits in scalability, flexibility, and cost-efficiency. However, its growth has introduced critical security challenges, particularly in the form of server-side attacks that exploit the dynamic and multi-tenant architecture of cloud environments. Currently, existing systems are faced with several limitations, including the difficulty in detecting and blocking server-side attacks in real time, challenges in accurately classifying evolving attack vectors, and the inability to ensure robust data isolation and privacy within shared infrastructures. This study developed an adaptive server-side attack detection and blocking system suitable for cloud computing environments. The developed system integrates a Neuro-Fuzzy Inference System for intelligent detection and blocking and employs Support Vector Machine for classifying sophisticated and previously unseen attack traffic patterns. To uphold data isolation and enhance privacy and security, the system incorporates the Cheon-Kim-Kim-Song scheme of Homomorphic Encryption (HE), ensuring that sensitive information (both in transit and at rest) remains secure. Furthermore, an Object-Oriented Design Approach was adopted for the designing and modelling of the system’s components. The implementation of the system was achieved using Visual Basic (VB) .Net 2022 for system interactive interface designing and coding with plugged-in Python programming language libraries for Machine Learning (ML) task. The system utilized the Microsoft Structured Query Language management studio as its database server. Seven network-based traffic features were selected as input variables to the developed system. These features are the Timestamp, Source IP, Destination IP, Source Port, Destination Port, Protocol, and Payload data. The developed system was trained using Backpropagation method, while the testing and performance evaluation was achieved using the Canadian Institute for Cybersecurity Intrusion Detection System 2017 (CICIDS2017) benchmark dataset. The developed system achieved a 99% accuracy rate in detection, a precision of 99.5%, recall of 99.5%, and an F1-score of 99.5%. In terms of performance in blocking malicious network traffic patterns, it recorded a True Negative Rate of 99.5% and a remarkably low False Positive Rate of 0.05%. Further, in privacy preservation, the encryption and decryption processes demonstrated average execution times of 112ms and 89ms, respectively, with a ciphertext expansion ratio of 1.5×, enabling secure processing without compromising performance. These results affirm that the developed system provides a robust, adaptive, and privacy-preserving solution for mitigating a broad spectrum of server-side attacks in cloud settings.
Keywords
References
More Articles from INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND MATHEMATICAL THEORY
Author: Michael Arnold and Fabio Vitor
Author: Ngozi Samuel Uzougbo, Michael Ominyi, Cyril Chimelie Anichukwueze, Blessing, Chika Jones
Author: Lawal Ahmed Oladimeji, Achori Busayo, Akeju BusayoZainab, Saka Samson, Damilare, Mbah Demian Chidi, Runsewe Similoluwa Mayowa, Oladiti Luqman, Abiodun
Author: Okolo Clement, Eluemuno
Author: Chukumeka Gift Iroanwusi, Davies Isobo Nelson
