Privilege Escalation Attack Detection and Mitigation in Cloud Using Machine Learning

Authors

  • Smt. P. Anitha1 , Molabanti Jagadeesh Babu 2 , Dabbakuti Venkata Tirupathi Raju 3 , Pittu Baji 4 , Thella Jessy Abhishek 5 , Machani Sai Kiran6 , Devarakonda Bhargav Sai Teja Author

DOI:

https://doi.org/10.62643/

Keywords:

Insider Threat Detection, Privilege Escalation, Ensemble Learning, LightGBM, CloudSecurity.

Abstract

The rapid increase in attack sophistication along with the expansion of smart connected devices has created serious cybersecurity concerns, especially in cloud environments. Although cloud computing offers major advantages to organizations, its centralized nature makes deploying distributed security systems difficult, and the continuous flow of sensitive information increases the chances of both accidental and intentional data breaches. Malicious insiders pose an even greater risk because they already possess legitimate privileges and can misuse them to cause extensive harm. This work introduces a machine-learning-based system designed to detect insider threats and classify suspicious behaviors related to privilege escalation. The framework analyzes cloud log activities to identify irregular patterns that may indicate security issues. Ensemble learning is used to improve prediction accuracy by combining multiple models. While earlier research has examined network anomalies, many methods do not effectively detect privilege-escalation attacks.To address this gap, a customized subset of the CERT insider threat dataset is used, and four ML models Random Forest, AdaBoost, XG Boost, and Light GBM are evaluated. Among these, Light GBM achieves the good accuracy, whereas While Light GBM offers the best overall performance, certain algorithms excel at detecting specific insider behaviors.

Downloads

Published

04-04-2026

How to Cite

Privilege Escalation Attack Detection and Mitigation in Cloud Using Machine Learning. (2026). International Journal of Engineering Research and Science & Technology, 22(2), 913-920. https://doi.org/10.62643/