Cloud systems now store enormous amounts of sensitive data, which makes them frequent targets for cyberattacks. Traditional security tools struggle to keep up with the scale and complexity of cloud environments, especially when investigators must analyze large volumes of log data after an incident. This study examines whether machine learning can improve anomaly detection in cloud forensics by focusing on Domain Name System (DNS) logs, which record critical user and network behavior. Using the BETH DNS dataset, eight unsupervised algorithms, Isolation Forest, DBSCAN, Local Outlier Factor, K-Nearest Neighbors, K-Means, Seasonal Decomposition, Mahalanobis Distance, and Autoencoder, were compared using accuracy, precision, recall, and F1 score. Seasonal Decomposition performed best, detecting 19 of 21 anomalies with 90.48 percent accuracy. These results show that time-series models are especially effective at identifying unusual patterns in cloud systems and can support more automated and scalable forensic investigations.
📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً