[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-126963-en":3,"doc-seo-126963-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},126963,687207024478,"Liam","https://ap-avatar.wpscdn.com/davatar_a8503ba1806abce46bf441b54a3ca4cd",8,"Research & Report","Detecting the Abuse of Cloud Services for C&C Infrastructure Through Dynamic Analysis and Machine Learning","Cybercriminals increasingly misuse cloud and legitimate services as covert command and control (C&C) infrastructure to coordinate malicious operations and evade security monitoring. The paper presents a detection system that combines dynamic analysis with machine learning to differentiate benign from malicious cloud interactions. A comprehensive VirusTotal-derived dataset supports feature extraction from host behavior and network traffic using Cuckoo and Triage sandboxes. Results show nearly 98% accuracy and stronger robustness against adversarial attacks that manipulate feature values.","ORCA – Online Research @  \nCardiff  \nThis is an Open Access document downloaded from ORCA, Cardiff University's institutional repository:[https://orca.cardiff.ac.uk/id/eprint/174655/](https://orca.cardiff.ac.uk/id/eprint/174655/)  \nThis is the author’s version of a work that was submitted to / accepted for publication.  \nCitation for final published version:  \nAl Lelah, Turki, Theodorakopoulos, George , Javed, Amir and Anthi, Eirini 2024. Detecting the abuse of cloud services for C&C infrastructure through dynamic analysis and machine learning. Presented at: 2024 International Symposium on Networks, Computers and Communications (ISNCC), Washington DC, USA, 22-25 October 2024. 2024 International Symposium on Networks, Computers and Communications (ISNCC) . IEEE, pp. 1-7. 10.1109/isncc62547.2024.10758940  \nPublishers page: [https://doi.org/10.1109/isncc62547.2024.10758940](https://doi.org/10.1109/isncc62547.2024.10758940)  \nPlease note:  \nChanges made as a result of publishing processes such as copy-editing, formatting and page numbers may not be reflected in this version. For the definitive version of this publication, please refer to the published source. You are advised to consult the publisher’s version if you wish to cite this paper.  \nThis version is being made available in accordance with publisher policies. See [http://orca.cf.ac.uk/policies.html](http://orca.cf.ac.uk/policies.html) for usage policies. Copyright and moral rights for publications made  \navailable in ORCA are retained by the copyright holders.  \nDetecting the Abuse of Cloud Services for C&C Infrastructure Through Dynamic Analysis and  \nMachine Learning  \nTurki Al lelah, George Theodorakopoulos, Amir Javed, Eirini Anthi  \nSchool of Computer Science and Informatics  \nCardiff University  \nCardiff, UK  \nEmail: {allelaht,theodorakopoulosg,javeda7,[anthies](anthies}@cardiff.ac.uk)[}](anthies}@cardiff.ac.uk)[@cardiff.ac.uk](anthies}@cardiff.ac.uk)  \nAbstract—Cybercriminals increasingly abuse cloud and legitimate services (CLS) as covert command and control (C&C) infrastructure to orchestrate malicious operations and evade detection. This paper addresses the critical challenge of detecting such abuse of cloud platforms. We introduce a detection system that integrates dynamic analysis with Machine Learning (ML) to accurately distinguish between benign and malicious interactions with cloud services. By utilising a comprehensive data set from VirusTotal, the system uses advanced feature extraction techniques from both host behaviour and network traffic, using Cuckoo and Triage sandboxes to extract behaviors, to develop a detection model. The results demonstrate that the model achieves nearly 98% accuracy in identifying cloud service abuse, substantially outperforming previous efforts. Furthermore, we evaluate the model’s robustness against adversarial attacks that aim to decrease accuracy by manipulating the feature values. Comparative evaluations show that our method maintains a higher detection accuracy under attack compared to related systems.  \nIndex Terms—Cloud computing security, Command and control, Malware detection, Machine learning, Dynamic analysis, Adversarial machine learning attack  \nI. INTRODUCTION  \nThe digital landscape is undergoing a rapid transformation, highlighted by the increasing reliance on cloud and legitimate services (CLS) in critical sectors such as healthcare, finance, education and government. This dependence is driving the global public cloud services market towards an anticipated value of $2.5 trillion by 2031, according to research by Allied Market Research (AMR) [1], up from $551.8 billion in 2021 . CLS deployment can save organisations more than 35% of their annual operating costs. By 2028, cloud computing will shift from being a technology disruptor to becoming a necessary component for maintaining business competitiveness. Gartner [2] predicts that more than 50% of enterprises will use industry cloud platforms by 2028 to accelera","cbCaipkGAvERPPt5","https://ap.wps.com/l/cbCaipkGAvERPPt5","pdf",410361,1,7,"English","en",105,"# Abstract\n# Index Terms\n# Introduction","[{\"question\":\"What problem does the paper address?\",\"answer\":\"The paper addresses detecting abuse of cloud and legitimate services when they are used as covert command and control (C\\u0026C) infrastructure to orchestrate malicious activity and evade detection.\"},{\"question\":\"How does the proposed detection system work?\",\"answer\":\"It integrates dynamic analysis with machine learning, extracting features from host behavior and network traffic using Cuckoo and Triage sandboxes to distinguish benign and malicious interactions.\"},{\"question\":\"How effective is the method and how is robustness evaluated?\",\"answer\":\"The model achieves nearly 98% accuracy and is evaluated for robustness against adversarial attacks designed to reduce accuracy by manipulating feature values, where comparative results show improved detection under attack.\"}]","Detecting the Abuse of Cloud Services for C&C Infrastructure Through Dynamic Analysis and Machine Learning | PDF",1785935932,18,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"detecting-the-abuse-of-cloud-services-for-cc-infrastructure-through-dynamic-analysis-and-machine-learning","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/detecting-the-abuse-of-cloud-services-for-cc-infrastructure-through-dynamic-analysis-and-machine-learning/126963/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-05",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does the paper address?","Question",{"text":75,"@type":76},"The paper addresses detecting abuse of cloud and legitimate services when they are used as covert command and control (C&C) infrastructure to orchestrate malicious activity and evade detection.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does the proposed detection system work?",{"text":80,"@type":76},"It integrates dynamic analysis with machine learning, extracting features from host behavior and network traffic using Cuckoo and Triage sandboxes to distinguish benign and malicious interactions.",{"name":82,"@type":73,"acceptedAnswer":83},"How effective is the method and how is robustness evaluated?",{"text":84,"@type":76},"The model achieves nearly 98% accuracy and is evaluated for robustness against adversarial attacks designed to reduce accuracy by manipulating feature values, where comparative results show improved detection under attack.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,119,122,127,130,134],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":21,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]