用XGBoost提前识别云中恶意用户,防止数据泄露
MAIDS: Malicious Agent Identification-based Data Security Model for Cloud Environments
- 基于多安全参数构建行为分析模型
- 通过预测潜在恶意行为实现事前防护
- 适合关注云数据安全的系统设计者
随着云计算快速发展,越来越多组织将数据与应用迁移至云端进行存储、计算和共享。在跨实体的数据共享过程中,恶意代理可能非法获取外包数据,导致信息被滥用或泄露。因此,数据保护与恶意代理预测成为亟需解决的关键问题。本文提出一种基于恶意代理识别的数据安全模型(MAIDS),利用XGBoost机器学习分类算法,对云环境中不同参与实体间的数据分配与通信进行安全防护。该模型综合评估多项在线数据交互的安全参数,并构建面向安全的知识数据库,用于训练基于XGBoost的恶意代理预测单元(XC-MAP)。与现有仅在数据泄露后识别恶意代理的方法不同,MAIDS通过评估代理的数据访问资格,实现对恶意行为的主动预警。该模型通过行为分析与预测,在授权前即排除潜在威胁,为关键数据提供从意图到执行层面的全流程防护。
原文摘要 · Abstract (English)
With the vigorous development of cloud computing, most organizations have shifted their data and applications to the cloud environment for storage, computation, and sharing purposes. During storage and data sharing across the participating entities, a malicious agent may gain access to outsourced data from the cloud environment. A malicious agent is an entity that deliberately breaches the data. This information accessed might be misused or revealed to unauthorized parties. Therefore, data protection and prediction of malicious agents have become a demanding task that needs to be addressed appropriately. To deal with this crucial and challenging issue, this paper presents a Malicious Agent Identification-based Data Security (MAIDS) Model which utilizes XGBoost machine learning classification algorithm for securing data allocation and communication among different participating entities in the cloud system. The proposed model explores and computes intended multiple security parameters associated with online data communication or transactions. Correspondingly, a security-focused knowledge database is produced for developing the XGBoost Classifier-based Malicious Agent Prediction (XC-MAP) unit. Unlike the existing approaches, which only identify malicious agents after data leaks, MAIDS proactively identifies malicious agents by examining their eligibility for respective data access. In this way, the model provides a comprehensive solution to safeguard crucial data from both intentional and non-intentional breaches, by granting data to authorized agents only by evaluating the agents behavior and predicting the malicious agent before granting data.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。