Network Threat Detection in IaaS Environments Based on Flow Log Data
DOI:
https://doi.org/10.26636/jtit.2026.3.2628Keywords:
AWS, cloud security, IaaS, intrusion detection, network traffic analysisAbstract
The rapid growth of cloud services has led security monitoring to rely mainly on limited telemetry data furnished by cloud service providers. Flow logs, such as VPC Flow Logs in Amazon Web Services, are one of the key sources of information about network traffic in IaaS environments. In this study, a fully automated experimental environment was designed and deployed in the AWS cloud using the infrastructure-as-a-code approach with Terraform. The environment includes a virtual network, flow logging mechanisms, and controlled attack scenarios generating characteristic traffic patterns, such as port scanning, brute-force authentication attempts, and data exfiltration. The collected data was analyzed using cloud-native tools, in particular Amazon Athena, which enabled a detailed investigation of anomaly detection based on flow-level metrics. The results confirm that selected threats can be effectively detected using traffic metadata, including the number of unique destination ports, the repetition of communication attempts, the volume of transferred data and the temporal regularity of flows. The analysis demonstrates that flow logs alone are not sufficient to clearly distinguish between malicious activity and legitimate operations with similar characteristics, highlighting inherent limitations of telemetry in the IaaS model. The paper outlines directions for future work, including correlation with additional log sources and integration with ML models to improve detection accuracy and reduce false positives.
Downloads
References
[1] S. Kanthed, "Monitoring of Cloud Computing Environments: Concepts, Solutions, Trends, and Future Directions", International Journal on Science and Technology, vol. 15, pp. 1-16, 2024. DOI: https://doi.org/10.71097/IJSAT.v15.i1.2836
View in Google Scholar
[2] A. Mycek, "Monitoring, Management, and Analysis of Security Aspects of IaaS Environments", Journal of Telecommunications and Information Technology, vol. 94, pp. 108-116, 2023. DOI: https://doi.org/10.26636/jtit.2023.4.1419
View in Google Scholar
[3] S. Shetty, B. Biswal, and H. Maziku, "Auditing and Analysis of Network Traffic in Cloud Environment", International Journal of Business Process Integration and Management, vol. 7, pp. 153-165, 2014. DOI: https://doi.org/10.1504/IJBPIM.2014.063519
View in Google Scholar
[4] B. Thomas et al., "A Study of Cloud-native Intrusion Detection Using VPC Flow Logs and Ensemble Learning", International Journal of Advanced Research in Computer and Communication Engineering, vol. 15, pp. 985-993, 2026. DOI: https://doi.org/10.17148/IJARCCE.2026.151131
View in Google Scholar
[5] H.B. Illa, "AI-Driven Incident Detection Using AWS CloudWatch and VPC Flow Logs", South Asian Journal of Engineering and Technology, vol. 14, pp. 70-85, 2024.
View in Google Scholar
[6] M. Collins et al., "Superflows: A New Tool for Forensic Network Flow Analysis", arXiv, 2024.
View in Google Scholar
[7] K. Hsieh et al., "NetVigil: Robust and Low-cost Anomaly Detection for East-West Data Center Security", 21st USENIX Symposium on Networked Systems Design and Implementation (NSDI 24), pp. 1771-1789, 2024.
View in Google Scholar
[8] Z. Wang et al., "Diagnosing Application-network Anomalies for Millions of IPs in Production Clouds", 2024 USENIX Annual Technical Conference (USENIX ATC 24), pp. 885-899, 2024.
View in Google Scholar
[9] M.S. Islam et al., "Anomaly Detection in Large-scale Cloud Systems: An Industry Case and Dataset", 2025 IEEE/ACM 47th International Conference on Software Engineering: Software Engineering in Practice (ICSE-SEIP), Ottawa, Canada, 2025. DOI: https://doi.org/10.1109/ICSE-SEIP66354.2025.00039
View in Google Scholar
[10] J. Kalibjian, "Security Considerations When Performing Telemetry Post-processing and Analysis in Cloud Environments", International Telemetering Conference Proceedings, vol. 58, 2023.
View in Google Scholar
[11] W. Dawoud, I. Takouna, and C. Meinel, "Infrastructure as a Service Security: Challenges and Solutions", 2010 The 7th International Conference on Informatics and Systems (INFOS), Cairo, Egypt, 2010.
View in Google Scholar
[12] F. Minna et al., "Understanding the Security Implications of Kubernetes Networking", IEEE Security & Privacy, vol. 19, pp. 46-56, 2021. DOI: https://doi.org/10.1109/MSEC.2021.3094726
View in Google Scholar
[13] A. Mycek and M. Łukaczyk, "Security and Hardening of Kubernetes in Public Clouds: A Comparative Study of EKS, AKS, and GKE", IEEE Access, vol. 14, pp. 80990-81009, 2026. DOI: https://doi.org/10.1109/ACCESS.2026.3697610
View in Google Scholar
[14] T.A.K. Manne, "Leveraging AWS Security Hub and GuardDuty for Continuous Threat Intelligence", The Journal of Scientific and Engineering Research, vol. 11, pp. 268-275, 2024.
View in Google Scholar
[15] A. Mycek, D. Grzonka, and J. Tchórzewski, "Agent-based Simulation and Analysis of Infrastructure-as-Code Process to Build and Manage Cloud Environment", Proc. of the 37th ECMS International Conference on Modelling and Simulation, pp. 513-520, 2023. DOI: https://doi.org/10.7148/2023-0513
View in Google Scholar
[16] A. Mycek and M. Łukaczyk, "Security of Containerization Platforms: Threat Modelling, Vulnerability Analysis, and Risk Mitigation", Proc. of the 38th ECMS International Conference on Modelling and Simulation, pp. 585-591, 2024. DOI: https://doi.org/10.7148/2024-0585
View in Google Scholar
[17] M. Łukaczyk and A. Mycek, "Automation of Security Policies in DevSecOps Environments: Implementation of Zero Trust Principles Using Ansible and Terraform in Linux Systems", Proc. of the 39th ECMS International Conference on Modelling and Simulation, pp. 241-247, 2025. DOI: https://doi.org/10.7148/2025-0241
View in Google Scholar
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Hubert Wójcik, Mirosław Roszkowski, Andrzej Mycek

This work is licensed under a Creative Commons Attribution 4.0 International License.