Supervised Classification of Cloud Workload Behavior Using Out-of-Band Performance Metrics
DOI:
https://doi.org/10.34190/eccws.25.1.4605Keywords:
Cloud performance metrics, Containerized workloads, Machine learning, Workload classification, Digital forensicsAbstract
Technological advances have significantly improved the flexibility, scalability, and efficiency of computing resource utilization. The adoption of orchestration systems to manage virtual containers is one such example. In these environments, containers can be deployed for the duration of a task and then removed to release resources back to the system. While orchestrated containerization allows for efficient and flexible use of computing resources, concerns have been raised about the ability to detect anomalous behavior and to conduct forensics investigations in the environment. Monitoring temporal readings of system performance metrics offers a potential solution to anomalous behavior detection, and storing the performance readings away from the transient containers could be a solution to support forensic investigations. However, the resultant storage can become expansive over time, making it an expensive and often-impractical solution. In this research, we analyze temporal readings of out-of-band performance metrics gathered from various layers of the technology stack while trials of four distinct benchmarking workloads were running. Our objective was to determine if machine learning (ML) techniques could reliably distinguish between the running workloads based on the performance metrics. After conducting proof-of-concept experiments using various ML methods, we applied a random forest classifier to all readings and metrics in our datasets. The classifier was able to identify with a high degree of accuracy the workload that was running on the system based upon the readings. Furthermore, we found that a relatively small subset of the performance metrics was significant for accurate classification. This indicates that the problem of extensive storage and processing requirements could be improved. Our results indicate that a ML model trained on patterns of normal behavior could be used to monitor live metrics for the purpose of anomaly detection. These findings support the feasibility of using continuously collected performance metrics to enable real-time anomaly detection and improve forensic readiness in environments where logging may be transient or incomplete such as in orchestrated container systems.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 European Conference on Cyber Warfare and Security

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.