Method Article

Utilizing Adaptive Machine Learning Algorithms for Information Risk Warning and Network Security Scenario Awareness in Cloud Computing Environments

DOI:

10.3791/69633

June 2nd, 2026

In This Article

Summary

Loading...
$$\rightleftharpoonup{xx}$$ $$\longleftharp{xx}$$, $$\longrightharp{xx}$$,

The paper proposes a novel Machine Learning (ML)-based solution of adaptive network security in a cloud-based system that integrates hierarchical multi-label classification and a dynamic trust evaluation system to advance the accuracy of threat detection and decrease the number of false positives.

Abstract

Loading...
$$\rightleftharpoonup{xx}$$ $$\longleftharp{xx}$$, $$\longrightharp{xx}$$,

This study proposes a novel framework for network security situational awareness and risk warning in cloud computing environments, integrating adaptive Machine Learning (ML), Hierarchical Multi-Label Classification (HMC), and a dynamic trust evaluation mechanism based on the cloud model. The complexity, diversity, and real-time nature of emerging cyberattacks-such as zero-day exploits, distributed denial-of-service (DDoS), and botnets-pose significant challenges to traditional rule-based and static detection methods. To address these challenges, we developed an effective SDN-based cloud architecture utilizing the Ryu OpenFlow controller and OpenFlow switches. This architecture enables real-time link information collection, dynamic scheduling, and scalable, reliable data transmission. The hierarchical classification framework suggested can break multiclass problems into binary tasks, alleviating the effect of sample imbalance and enhancing the recognition of low-frequency attacks, including User to Root (U2R). Ensemble learning techniques, including AdaBoost and Bagging, further enhance detection accuracy for fine-grained attack types. Experiments conducted on DDoS datasets, cloud traffic data, and simulations in Mininet and EstiNet demonstrate that the combined ML-HMC-trust approach significantly improves detection precision, reduces false positives, and enables real-time response. These results confirm that integrating adaptive learning, hierarchical classification, and dynamic trust evaluation provides a robust and scalable solution for securing large-scale cloud platforms.

Introduction

Loading...
$$\rightleftharpoonup{xx}$$ $$\longleftharp{xx}$$, $$\longrightharp{xx}$$,

With the widespread application of cloud computing technology in various industries, the scale and amount of data in information systems are increasing rapidly, and network threats are becoming more complex, hidden, and dynamic1,2. Traditional security defense mechanisms based on rules and static models are no longer able to meet the requirements of real-time detection with accurate early warning when facing changing attack strategies, zero-day vulnerabilities, and large-scale distributed attacks3. Therefore, leveraging adaptive ML algorithms to fully integrate distributed data processi....

Access restricted. Please log in or start a trial to view this content.

Protocol

Loading...
$$\rightleftharpoonup{xx}$$ $$\longleftharp{xx}$$, $$\longrightharp{xx}$$,

NOTE: This protocol describes how to construct a cloud-based network security situational awareness system and implement hierarchical classification with dynamic trust evaluation. Follow the steps below to design the cloud network topology, collect and annotate data flows, and deploy the hierarchical multiclass classification and trust assessment modules. Figure 1 illustrates the proposed SDN-cloud framework integrating adaptive ML, hierarchical classification, and trust evaluation for real-time attack detection .

1. Cloud network topology design

NOTE: Ensure administrative access to O....

Access restricted. Please log in or start a trial to view this content.

Results

Loading...
$$\rightleftharpoonup{xx}$$ $$\longleftharp{xx}$$, $$\longrightharp{xx}$$,

Experimental validation and performance analysis

Cloud-based validation

To test the efficiency and feasibility of the proposed algorithm, simulation tests were performed in a controlled network laboratory setting. The verification was conducted on the Windows operating system, and the core algorithm is coded in VC (Visual C++) programming tools.

In case of experimental data, we chose the publicly availabl.......

Access restricted. Please log in or start a trial to view this content.

Discussion

Loading...
$$\rightleftharpoonup{xx}$$ $$\longleftharp{xx}$$, $$\longrightharp{xx}$$,

An effective deployment of this protocol relies on critical steps within the cloud-based architecture. Proper configuration of the Ryu OpenFlow controller, correct setup of Open vSwitch rules, and robust formation of a multi-layer topology are essential to ensure full traffic capture. The selection of Ryu as the controller and Open vSwitch as the switching platform significantly strengthens the system's practical value; their lightweight, modular, and fully programmable characteristics make them ideal for real-time netwo.......

Access restricted. Please log in or start a trial to view this content.

Disclosures

Loading...
$$\rightleftharpoonup{xx}$$ $$\longleftharp{xx}$$, $$\longrightharp{xx}$$,

The authors have nothing to disclose.

Acknowledgements

Loading...
$$\rightleftharpoonup{xx}$$ $$\longleftharp{xx}$$, $$\longrightharp{xx}$$,

The authors express their gratitude to the Department of Information at the Shanghai Proton and Heavy Ion Center for providing the essential computing resources and research environment required for this study. We also extend our appreciation to our colleagues for their valuable technical insights during the system design and testing phases.

....

Access restricted. Please log in or start a trial to view this content.

Materials

List of materials used in this article
NameCompanyCatalog NumberComments
AdaBoost (Ensemble Learning Library)Scikit-learn, Pythonhttps://scikit-learn.org/stable/modules/generated/sklearn.ensemble.AdaBoostClassifier.htmlSoftware
Bagging ClassifierScikit-learn, Pythonhttps://scikit-learn.org/stable/modules/generated/sklearn.ensemble.BaggingClassifier.htmlSoftware
Cloud Model Trust Evaluation CodeCustom implementationN/AAlgorithm/Software
Convolutional Neural Network (CNN)TensorFlow / PyTorchhttps://www.tensorflow.org/tutorials/images/cnnSoftware
Deep Learning Frameworks (MLP, RNN, LSTM, GRU)TensorFlow / PyTorchSoftware
EstiNet Network SimulatorEstiNet Technologieshttps://sites.google.com/view/estinet-network-simulatorSoftware
Kafka (Data Streaming Platform)Apache Foundationhttps://kafka.apache.org/Software
KDD CUP 10% DatasetUCI Machine Learning Repositoryhttp://kdd.ics.uci.edu/databases/kddcup99/kddcup99.htmlDataset
Mininet EmulatorMininet ProjectMininet 2.3.1Network emulation for SDN topology, bandwidth, and mixed attack simulation.
Open vSwitch (OVS)Open vSwitch OrgOVS 3.2.2Virtual switch implementing flow-table control and attack traffic redirection.
OpenStack Cloud PlatformOpen Infrastructure Foundationhttps://www.openstack.org/Cloud Software
Python 3.xPython Software Foundationhttps://www.python.org/downloads/Programming Language
Ryu SDN ControllerNTT R&DRyu 4.34SDN controller for real-time network traffic capture and situation awareness.
Spark Streaming FrameworkApache Foundationhttps://spark.apache.org/docs/latest/streaming-programming-guide.htmlSoftware
Visual C++ (VC++) CompilerMicrosofthttps://visualstudio.microsoft.com/Software
Windows 11 WorkstationMicrosoftWindows 11 Pro 23H2OS used for model compilation, training, and testing.

References

Loading...
$$\rightleftharpoonup{xx}$$ $$\longleftharp{xx}$$, $$\longrightharp{xx}$$,
  1. Xie, J. Application study on the reinforcement learning strategies in the network awareness risk perception and prevention. Int J Comput Intell Syst. 17 (1), 112(2024).
  2. Research on enhancing cloud computing network security using artificial intelligence algorithms. Wang, Y., Yang, X. 2025 International Conference on Sensor-Cloud and Edge Computing System (SCECS), Zhuhai, China, , 237-244 (2025).

Access restricted. Please log in or start a trial to view this content.

Reprints and Permissions

Request permission to reuse the text or figures of this JoVE article

Request Permission

Tags

Hierarchical ClassificationTrust EvaluationDDoS DetectionEnsemble LearningSDN ArchitectureReal Time Response

Related Articles