$$\rightleftharpoonup{xx}$$
$$\longleftharp{xx}$$,
$$\longrightharp{xx}$$,
With the widespread application of cloud computing technology in various industries, the scale and amount of data in information systems are increasing rapidly, and network threats are becoming more complex, hidden, and dynamic1,2. Traditional security defense mechanisms based on rules and static models are no longer able to meet the requirements of real-time detection with accurate early warning when facing changing attack strategies, zero-day vulnerabilities, and large-scale distributed attacks3. Therefore, leveraging adaptive ML algorithms to fully integrate distributed data processing and intelligent analysis capabilities within cloud computing platforms to achieve a comprehensive perception of network security situation and effective early warning of information risks represents a critical challenge in the current information security landscape4. This research not only has important theoretical significance for improving the existing security protection system, but also offers strong support for ensuring the security of the national key information infrastructure and enterprise core data5.
There are multiple challenges in realizing network security situation awareness and information risk warning in a cloud computing environment: data types aggregated in the cloud platform are numerous and the sources are complex, making data preprocessing, feature extraction and fusion tasks increasingly arduous; in the face of the increasing network traffic and rapidly changing attack scenarios, the system is required to respond in a very short time, and real-time detection and warning have become technical bottlenecks; the amount of normal traffic is very different from that of attack traffic, and traditional algorithms have low accuracy when processing small sample categories (such as U2R, network attacks, etc.), and there is a large risk of misjudgment; in a complex network environment, trust relationships are affected by multiple factors and are random and uncertain6,7. Traditional trust assessment methods based on fixed thresholds are difficult to reflect the real state and are easily interfered with by abnormal data. To address these multi-dimensional limitations, this research presents an integrated framework that synergizes adaptive machine learning, hierarchical multi-label classification, and a dynamic cloud-model-based trust evaluation mechanism. This fusion of techniques applied within an SDN-driven cloud environment goes beyond incremental refinement by enabling fine-grained recognition of low-frequency attacks, real-time trust adaptation, and scalable situational awareness, which existing methods have not simultaneously achieved.
Cloud computing environments generate massive, highly dynamic, and heterogeneous network traffic, making traditional intrusion detection systems (IDS) unable to accurately identify sophisticated and minority attack types such as U2R and R2L. Existing deep learning (DL)-based IDS solutions improve detection accuracy but still suffer from high computational overhead, slow real-time response, and poor handling of uncertain or evolving trust relationships between network entities. Moreover, most current models operate as flat classifiers and lack mechanisms for fine-grained, hierarchical decision-making or dynamic trust evaluation. These limitations create a critical gap in developing an IDS that can simultaneously deliver real-time detection, accurate minority-class recognition, and reliable trust-aware risk assessment in large-scale cloud environments.
In the existing research on network security situation awareness and information risk warning, many studies use methods such as K-nearest neighbor (KNN) and support vector machine (SVM) to classify and detect network traffic. These algorithms have the advantages of high computational efficiency and easy implementation, especially when performing preliminary screening of large amounts of data8,9. However, their main shortcomings are reflected in several aspects: when faced with most normal traffic and a small number of attack samples in a cloud environment, these traditional ML methods often ignore information from a few categories, resulting in low recognition rates for fine-grained attacks (such as U2R, network vulnerability attacks, etc.); single models are usually sensitive to noise and data outliers, lack the capability to adapt to dynamically changing attack scenarios, and are prone to overfitting or insufficient generalization10,11.
In recent years, DL methods such as Multi-Layer Perceptron (MLP), CNN, Recurrent Neural Network (RNN), Long Short-Term Memory Network (LSTM), and Gated Recurrent Unit (GRU) have been increasingly applied in the field of network security. With the powerful feature-learning and nonlinear-mapping capabilities of deep neural networks, these methods have significantly improved detection accuracy and enhanced the ability to capture complex attack behaviors compared to traditional ML12. However, they have high requirements for computing resources and training data. Especially in the big data traffic context in cloud computing environments, there is still room for improvement in training overhead and real-time inference speed. When identifying classes with few samples, due to data imbalance, DL models have low detection rates for some fine-grained attacks (such as U2R, botnets) due to class bias13. To make up for the limitations of a single model in dealing with data imbalance and multiclass attack identification, some studies have proposed ensemble learning-based solutions, such as Bagging and Boosting, which expand the overall prediction accuracy by combining decisions of multiple classifiers14. At the same time, the Hierarchical Multiclass Classification (HMC) architecture decomposes the multiclass classification problem into multiple binary classification sub-problems, thereby achieving more refined recognition for classes with fewer samples. However, integrated models often face problems such as high computing resource usage and increased response time during deployment, especially in cloud computing real-time monitoring systems, where real-time requirements increase the pressure on system resources15.
In response to the problem of dynamic trust relationship evaluation in the network, some studies have introduced cloud model theory, which constructs a trust affiliation cloud by describing the fuzziness and randomness of the trust attributes of each entity, and then uses cloud droplets, entropy, super entropy, and other indicators for quantitative evaluation16. When facing real-time updated network trust data, the update rate and computational efficiency of existing cloud model methods may find it difficult to meet the requirements of high-frequency dynamic warning; the model is highly sensitive to evaluation data, and abnormal data or noise information may have a significant interference with the overall trust evaluation, affecting subsequent risk warning decisions.
In view of the many shortcomings of current research in detection accuracy, real-time performance, data balance processing, and trust evaluation, this paper proposes a new defense system that comprehensively utilizes adaptive ML algorithms, hierarchical multiclass classification strategies, and cloud model trust evaluation for network security situation awareness and information risk warning in cloud computing environments17.
The research addresses real-time cybersecurity for intelligent ship networks by leveraging cloud computing technology18. It suggests a multi-sensor node framework to examine data for malicious attacks and uses self-executing protection strategy nodes to intercept threats. Results demonstrate a virus intrusion detection and defense rate of 85-95%, and a False Positive Rate of 2.56%, significantly outperforming other algorithms. However, the approach requires high computational resources and cloud infrastructure restrictions in practical deployment. Aslan et al.19 provide an intelligent behavior-based malware detection system in a cloud computing environment. It produced a malware dataset across virtual machines and used selected features with learning-based and rule-based detection agents to classify malware and benign samples. Assessment on 10,000 program samples showed a high performance with improved detection rate and FPR. Nonetheless, the method had scalability issues with constantly changing malware variants and cloud deployments on scale and in real-time.
Despite the significant contributions made by these studies, a more detailed comparison reveals that the majority of existing solutions fail to address the assumptions and requirements of real-time situation awareness or the dynamic trust model in cloud-based environments. Conventional ML techniques assume feature boundaries that are fixed in space and fail in class imbalance and highly dynamic traffic dynamics8,9,10. DL models are associated with excellent feature extraction abilities but consume high computational power, which makes the process of inference slow and impractical in real-time monitoring12,13. Ensemble and HMC-based approaches are more accurate, but need even more latency and resources, and are currently not deployed in large-scale clouds14,15. Meanwhile, cloud-model trust evaluation techniques capture uncertainty well but remain highly sensitive to noisy data and cannot update trust values efficiently under high-frequency attack streams16,17,18,19. Even recent cloud-based IDS frameworks lack robust, integrated support for both real-time detection and trust-aware decision-making20,21. These restrictions collectively highlight the necessity for an efficient, unified, and trust-enabled intrusion detection framework. This research overcomes these limitations by integrating adaptive ML, HMC, and cloud-model-based dynamic trust evaluation within an SDN-enabled cloud architecture, enabling real-time detection, improved minority-class accuracy, and uncertainty-aware risk assessment.
The innovations of this paper are mostly reflected in the following aspects: An efficient distributed network architecture based on the Ryu OpenFlow controller and OpenFlow switch is constructed to enable real-time collection and dynamic scheduling of link information, thereby greatly improving data transmission efficiency and processing.
In view of the difficulties posed by data imbalance and few-sample attack identification, a top-down HMC framework is designed, and integrated learning methods such as AdaBoost and Bagging are introduced to significantly improve the detection accuracy of fine-grained attack categories.
The cloud model theory is used to build a trust affiliation cloud. Through the reverse generator and similarity calculation, the dynamic evaluation of the trust status of each entity in the network is realized, providing a quantitative basis for risk warning and effectively suppressing the credit speculation caused by abnormal transactions at low or high prices.