Network Threat Detection in IaaS Environments Based on Flow Log Data
Abstract
The rapid growth of cloud services has led security monitoring to rely mainly on limited telemetry data furnished by cloud service providers. Flow logs, such as VPC Flow Logs in Amazon Web Services, are one of the key sources of information about network traffic in IaaS environments. In this study, a fully automated experimental environment was designed and deployed in the AWS cloud using the infrastructure-as-a-code approach with Terraform. The environment includes a virtual network, flow logging mechanisms, and controlled attack scenarios generating characteristic traffic patterns, such as port scanning, brute-force authentication attempts, and data exfiltration. The collected data was analyzed using cloud-native tools, in particular Amazon Athena, which enabled a detailed investigation of anomaly detection based on flow-level metrics. The results confirm that selected threats can be effectively detected using traffic metadata, including the number of unique destination ports, the repetition of communication attempts, the volume of transferred data and the temporal regularity of flows. The analysis demonstrates that flow logs alone are not sufficient to clearly distinguish between malicious activity and legitimate operations with similar characteristics, highlighting inherent limitations of telemetry in the IaaS model. The paper outlines directions for future work, including correlation with additional log sources and integration with ML models to improve detection accuracy and reduce false positives.