Behavioral Analysis and Machine Learning for Unauthorized Privilege Escalation Detection
Keywords:
Cloud Security , Privilege Escalation , Insider Threat Detection , Machine Learning, Ensemble Learning, CERT Dataset , Random Forest , XGBoost , LightGBMAbstract
The objective of this paper is to identify instances of unlawful privilege escalation in contemporary computer systems through the application of machine learning and behavioral analysis. Privilege escalation assaults are a method by which malicious individuals or programs can obtain increased access levels without obtaining permission. This could jeopardize the organization's reputation, data privacy, and system security. The paper proposes an improved system for identifying suspicious command executions, unusual access patterns, and unusual user behaviors in real time. This system would integrate robust machine learning algorithms with user activity data. The system's capacity to identify hazards promptly and accurately is enhanced by the utilization of controlled and unsupervised learning models, including Deep Learning, Support Vector Machines, Random Forests, and Decision Trees, which simultaneously decrease the incidence of false positives. The primary objective of the investigation is to enhance the precision of predictions by extracting features from authentication data, system records, and network events. Experiments have demonstrated that the proposed system is capable of detecting a potential attempt to unlawfully increase privileges. This feature enables you to prevent threats from occurring in the cloud and in business contexts, thereby improving safety.
