Privilege Escalation Attack Detection and Mitigation in Cloud Using Machine Learning

  • Unique Paper ID: 197698
  • Volume: 12
  • Issue: 11
  • PageNo: 8454-8467
  • Abstract:
  • Cloud computing has revolutionised modern digital infrastructure by providing scalable, flexible, and on-demand access to computational resources and storage. However, the rapid adoption of cloud technologies has simultaneously introduced severe security challenges, of which privilege escalation by malicious insiders represents one of the most damaging and difficult-to-detect threats. Unlike external attackers, insiders already possess legitimate credentials and access rights, making their anomalous activities difficult to distinguish from normal behaviour using rule-based or signature-based security tools. This paper proposes and evaluates a comprehensive machine learning-based framework for detecting and mitigating insider-driven privilege escalation attacks in cloud environments. A customised dataset derived from the widely studied CERT Insider Threat Dataset is utilised, incorporating 830 behavioural and access-log features from real-world organisational scenarios. Five ensemble learning algorithms are implemented and rigorously compared: Random Forest (RF), AdaBoost, XGBoost, LightGBM, and CatBoost — the latter introduced as an extension over prior work. Experimental results demonstrate that CatBoost achieves the highest accuracy of 97%, outperforming RF (92%), AdaBoost (88%), XGBoost (88.27%), and LightGBM (95%) on the same test partition. Each model is evaluated using accuracy, precision, recall, F1-score, and confusion matrices, providing a complete picture of detection capability across both normal and attack classes. The proposed system advances the state of the art in cloud insider threat detection by combining strong ensemble predictors with interpretable metrics, establishing a scalable and accurate foundation for real-world deployment.

Copyright & License

Copyright © 2026 Authors retain the copyright of this article. This article is an open access article distributed under the Creative Commons Attribution License which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.

BibTeX

@article{197698,
        author = {Dr Altaf C and Mohammed Abdullah Hussain and Mohammed Abdul Razzak and Mir Ahmed Ali and Mohammed Ghouse},
        title = {Privilege Escalation Attack Detection and Mitigation in Cloud Using Machine Learning},
        journal = {International Journal of Innovative Research in Technology},
        year = {2026},
        volume = {12},
        number = {11},
        pages = {8454-8467},
        issn = {2349-6002},
        url = {https://ijirt.org/article?manuscript=197698},
        abstract = {Cloud computing has revolutionised modern digital infrastructure by providing scalable, flexible, and on-demand access to computational resources and storage. However, the rapid adoption of cloud technologies has simultaneously introduced severe security challenges, of which privilege escalation by malicious insiders represents one of the most damaging and difficult-to-detect threats. Unlike external attackers, insiders already possess legitimate credentials and access rights, making their anomalous activities difficult to distinguish from normal behaviour using rule-based or signature-based security tools. This paper proposes and evaluates a comprehensive machine learning-based framework for detecting and mitigating insider-driven privilege escalation attacks in cloud environments. A customised dataset derived from the widely studied CERT Insider Threat Dataset is utilised, incorporating 830 behavioural and access-log features from real-world organisational scenarios. Five ensemble learning algorithms are implemented and rigorously compared: Random Forest (RF), AdaBoost, XGBoost, LightGBM, and CatBoost — the latter introduced as an extension over prior work. Experimental results demonstrate that CatBoost achieves the highest accuracy of 97%, outperforming RF (92%), AdaBoost (88%), XGBoost (88.27%), and LightGBM (95%) on the same test partition. Each model is evaluated using accuracy, precision, recall, F1-score, and confusion matrices, providing a complete picture of detection capability across both normal and attack classes. The proposed system advances the state of the art in cloud insider threat detection by combining strong ensemble predictors with interpretable metrics, establishing a scalable and accurate foundation for real-world deployment.},
        keywords = {Cloud Security; Privilege Escalation; Insider Threat Detection; Machine Learning; Ensemble Learning; CERT Dataset; Random Forest; XGBoost; LightGBM; CatBoost; Anomaly Detection.},
        month = {April},
        }

Cite This Article

C, D. A., & Hussain, M. A., & Razzak, M. A., & Ali, M. A., & Ghouse, M. (2026). Privilege Escalation Attack Detection and Mitigation in Cloud Using Machine Learning. International Journal of Innovative Research in Technology (IJIRT), 12(11), 8454–8467.

Related Articles