{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T16:50:08Z","timestamp":1783529408945,"version":"3.55.0"},"reference-count":23,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2025,3,17]],"date-time":"2025-03-17T00:00:00Z","timestamp":1742169600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,3,17]],"date-time":"2025-03-17T00:00:00Z","timestamp":1742169600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"name":"Manipal Academy of Higher Education, Manipal"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int J Comput Intell Syst"],"abstract":"<jats:title>Abstract<\/jats:title>\n          <jats:p>A Tenant Virtual Machine (TVM) user in the cloud may misuse its computing power to launch malware attack against other tenant VMs, Host OS, Hypervisor, or any other computing devices\/resources inside the cloud environment of a Cloud Service Provider. The security solutions deployed within the TVM may not be reliable, as malware can disable them or remain undetected due to its hidden nature. Therefore, security solutions deployed outside the virtual machine are necessary. This research proposes deploying an Intrusion Detection System (IDS) at the Hypervisor layer, utilizing time series system call data and employing a Convolutional Neural Network (CNN) model to accurately detect the presence of malicious (malware) computer programs within virtual machines. The raw VMM system call traces are transformed into novel Time Series System Call patterns and utilized by a deep learning algorithm for training and building the classifier model. A deep learning model, CNN, is used to build the classifier model for detecting intrusions with high accuracy. It is capable of detecting both known and unknown malware. The CNN model is compared with machine learning algorithms for the results and discussions, and it outperforms ML algorithms in terms of intrusion detection accuracy when utilizing novel time series system call data..<\/jats:p>","DOI":"10.1007\/s44196-025-00781-z","type":"journal-article","created":{"date-parts":[[2025,3,17]],"date-time":"2025-03-17T09:42:20Z","timestamp":1742204540000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":7,"title":["A Deep Learning Model Leveraging Time-Series System Call Data to Detect Malware Attacks in Virtual Machines"],"prefix":"10.1007","volume":"18","author":[{"given":"A. Alfred Raja","family":"Melvin","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jaspher W.","family":"Kathrine","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Andrew","family":"Jeyabose","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"D.","family":"Cenitta","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,3,17]]},"reference":[{"key":"781_CR1","unstructured":"[online]https:\/\/www.mcafee.com\/enterprise\/en-us\/assets\/reports\/rp-cloud-adoption-and-risk-report-work-from-home-edition.pdf"},{"key":"781_CR2","unstructured":"[online]https:\/\/www.fortinet.com\/content\/dam\/fortinet\/assets\/analyst-reports\/report-2022-cloud-security.pdf"},{"key":"781_CR3","doi-asserted-by":"publisher","DOI":"10.1002\/ett.4287","volume":"33","author":"A Melvin","year":"2021","unstructured":"Melvin, A., Kathrine, G.J., Ilango, S., Shanmuganthan, V., Rho, S., Xiong, N., Nam, Y.: Dynamic malware attack dataset leveraging virtual machine monitor audit data for the detection of intrusions in cloud. Trans. Emerg. Telecommun. Technol. 33, e4287 (2021). https:\/\/doi.org\/10.1002\/ett.4287","journal-title":"Trans. Emerg. Telecommun. Technol."},{"key":"781_CR4","doi-asserted-by":"publisher","first-page":"151","DOI":"10.3233\/JCS-980109","volume":"6","author":"SA Hofmeyr","year":"1998","unstructured":"Hofmeyr, S.A., Forrest, S., Somayaji, A.: Intrusion detection using sequences of system calls. J. Comput. Secur. 6, 151\u2013180 (1998)","journal-title":"J. Comput. Secur."},{"key":"781_CR5","doi-asserted-by":"crossref","unstructured":"Gupta S, Kumar P (2014) An immediate system call sequence based approach for detecting malicious program executions in cloud environment. Springer Science+Business Media: New York, USA","DOI":"10.1007\/s11277-014-2136-x"},{"key":"781_CR6","doi-asserted-by":"publisher","first-page":"807","DOI":"10.1109\/TC.2013.13","volume":"63","author":"G Creech","year":"2014","unstructured":"Creech, G., Hu, J.: A semantic approach to host-based intrusion detection systems using contiguousanddis contiguous system call patterns. IEEE Trans. Comput. 63, 807\u2013819 (2014)","journal-title":"IEEE Trans. Comput."},{"key":"781_CR7","unstructured":"Garfinkel T, Rosenblum M (2003) A virtual machine introspection based architecture for intrusion detection. Netw. Distrib Syst. Secur. Symp"},{"key":"781_CR8","volume":"51","author":"P Mishra","year":"2020","unstructured":"Mishra, P., Verma, I., Gupta, S.: KVMInspector: KVM based introspection approach to detect malware in cloud environment. J. Inf. Secur. Appl. 51, 102460 (2020)","journal-title":"J. Inf. Secur. Appl."},{"key":"781_CR9","doi-asserted-by":"publisher","first-page":"101646","DOI":"10.1016\/j.cose.2019.101646","volume":"88","author":"A Aldribi","year":"2020","unstructured":"Aldribi, A., Traor\u00e9, I., Moa, B., Nwamuo, O.: Hypervisor-based cloud intrusion detection through online multivariate statistical change tracking. Comput. Secur. 88, 101646 (2020). https:\/\/doi.org\/10.1016\/j.cose.2019.101646","journal-title":"Comput. Secur."},{"key":"781_CR10","doi-asserted-by":"publisher","first-page":"147","DOI":"10.1007\/s10207-019-00447-w","volume":"19","author":"R Patil","year":"2019","unstructured":"Patil, R., Dudeja, H., Modi, C.N.: Designing in-VM-assisted lightweight agent-based malware detection framework for securing virtual machines in cloud computing. Int. J. Inf. Secur. 19, 147\u2013162 (2019)","journal-title":"Int. J. Inf. Secur."},{"key":"781_CR11","doi-asserted-by":"publisher","first-page":"34","DOI":"10.1007\/s12046-018-1016-6","volume":"44","author":"B Borisaniya","year":"2019","unstructured":"Borisaniya, B., Patel, D.: Towards virtual machine introspection based security framework for cloud. S\u00e5dhan\u00e5 44, 34 (2019). https:\/\/doi.org\/10.1007\/s12046-018-1016-6","journal-title":"S\u00e5dhan\u00e5"},{"key":"781_CR12","doi-asserted-by":"publisher","first-page":"99","DOI":"10.1016\/j.diin.2017.10.004","volume":"23","author":"MA Kumara","year":"2017","unstructured":"Kumara, M.A., Jaidhar, C.D.: Leveraging virtual machine introspection with memory forensics to detect and characterize unknown malware using machine learning techniques at hypervisor. Digit. Investig. 23, 99\u2013123 (2017)","journal-title":"Digit. Investig."},{"key":"781_CR13","doi-asserted-by":"publisher","DOI":"10.1109\/TCC.2018.2829202]","author":"P Mishra","year":"2020","unstructured":"Mishra, P., Varadharajan, V., Pilli, E.S., Tupakula, U.: VMGuard: A VMIbased security architecture for intrusion detection in cloud environment. IEEE Trans. Cloud Comput. (2020). https:\/\/doi.org\/10.1109\/TCC.2018.2829202]","journal-title":"IEEE Trans. Cloud Comput."},{"key":"781_CR14","doi-asserted-by":"publisher","first-page":"375","DOI":"10.1109\/TCC.2016.2535320","volume":"5","author":"V Varadharajan","year":"2017","unstructured":"Varadharajan, V., Tupakula, U.K.: On the design and implementation of an integrated security architecture for cloud with improved resilience. IEEE Trans. Cloud Comput. 5, 375\u2013389 (2017)","journal-title":"IEEE Trans. Cloud Comput."},{"key":"781_CR15","volume":"78","author":"R-H Hwang","year":"2023","unstructured":"Hwang, R.-H., Lee, C.-L., Lin, Y.-D., Lin, P.-C., Hsiao-Kuang, Wu., Yuan-Cheng, L., Chen, C.K.: Host-based intrusion detection with multi-datasource and deep learning. J. Inform. Secur. Appl. 78, 103625 (2023)","journal-title":"J. Inform. Secur. Appl."},{"key":"781_CR16","volume":"68","author":"Y-D Lin","year":"2022","unstructured":"Lin, Y.-D., Wang, Z.-Y., Lin, P.-C., Nguyen, V.-L., Hwang, R.-H., Lai, Y.-C.: Multi-datasource machine learning in intrusion detection: packet flows, system logs and host statistics. J. Inform. Secur. Appl. 68, 103248 (2022). (ISSN 2214-2126)","journal-title":"J. Inform. Secur. Appl."},{"key":"781_CR17","doi-asserted-by":"publisher","first-page":"41525","DOI":"10.1109\/ACCESS.2019.2895334","volume":"7","author":"R Vinayakumar","year":"2019","unstructured":"Vinayakumar, R., Alazab, M., Soman, K.P., Poornachandran, P., Al-Nemrat, A., Venkatraman, S.: Deep learning approach for intelligent intrusion detection system. IEEE Access 7, 41525\u201341550 (2019). https:\/\/doi.org\/10.1109\/ACCESS.2019.2895334","journal-title":"IEEE Access"},{"key":"781_CR18","doi-asserted-by":"crossref","unstructured":"Chawla A, Lee BA, Fallon S, Jacob P (2018) Host Based Intrusion Detection System with Combined CNN\/RNN Model. Nemesis\/UrbReas\/SoGood\/IWAISe\/GDM@PKDD\/ECML","DOI":"10.1007\/978-3-030-13453-2_12"},{"key":"781_CR19","unstructured":"Hsiao S, Sun YS, Chen MC (2017) Virtual machine introspection based malware behavior profiling and family grouping. ArXiv, abs\/1705.01697"},{"key":"781_CR20","doi-asserted-by":"crossref","unstructured":"Warrender CE, Forrest S, Pearlmutter BA (1999) Detecting intrusions using system calls: alternative data models. Proceedings of the 1999 IEEE Symposium on Security and Privacy (Cat. No.99CB36344), 133\u2013145","DOI":"10.1109\/SECPRI.1999.766910"},{"key":"781_CR21","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3344382","volume":"52","author":"RA Bridges","year":"2018","unstructured":"Bridges, R.A., Glass-Vanderlan, T.R., Iannacone, M.D., Vincent, M.S., Chen, Q.: A survey of intrusion detection systems leveraging host data. ACM Comput. Surv. (CSUR) 52, 1\u201335 (2018)","journal-title":"ACM Comput. Surv. (CSUR)"},{"key":"781_CR22","doi-asserted-by":"publisher","first-page":"12218","DOI":"10.1007\/s11227-024-05895-3","volume":"80","author":"N Joraviya","year":"2024","unstructured":"Joraviya, N., Gohil, B.N., Rao, U.P.: DL-HIDS: deep learning-based host intrusion detection system using system calls-to-image for containerized cloud environment. J. Supercomput. 80, 12218\u201312246 (2024). https:\/\/doi.org\/10.1007\/s11227-024-05895-3","journal-title":"J. Supercomput."},{"key":"781_CR23","doi-asserted-by":"publisher","first-page":"3837","DOI":"10.1007\/s41870-024-01887-x","volume":"16","author":"E Silambarasan","year":"2024","unstructured":"Silambarasan, E., Suryawanshi, R., Reshma, S.: Enhanced cloud security: a novel intrusion detection system using ARSO algorithm and Bi-LSTM classifier. Int. j. inf. tecnol. 16, 3837\u20133845 (2024). https:\/\/doi.org\/10.1007\/s41870-024-01887-x","journal-title":"Int. j. inf. tecnol."}],"container-title":["International Journal of Computational Intelligence Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s44196-025-00781-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s44196-025-00781-z\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s44196-025-00781-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,3,17]],"date-time":"2025-03-17T09:42:28Z","timestamp":1742204548000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s44196-025-00781-z"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,3,17]]},"references-count":23,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["781"],"URL":"https:\/\/doi.org\/10.1007\/s44196-025-00781-z","relation":{},"ISSN":["1875-6883"],"issn-type":[{"value":"1875-6883","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,3,17]]},"assertion":[{"value":"28 October 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"23 February 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"17 March 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}],"article-number":"58"}}