Cloud-Native AI Frameworks for Proactive Cybersecurity Threat Detection
DOI:
https://doi.org/10.5281/zenodo.20442062Keywords:
Overreliance on signature-based sensor data, automation, and information sharing often enables threat actors to perpetrate cyberattacks such as ransomware, cryptojacking, and other undetected activities for months. Even without prior knowledge of an attack, security teams have the opportunity to locate advanced persistent threats that have already evaded existing security controls. Organizations must thus embrace threat hunting—proactively seeking active adversaries in their environments using tailored detection capabilities. Information technology teams operating in public cloud environments can now empower hunting by observing attack paths, developing detection capabilities in a serverless, on-demand, and cost-effective manner, and storing massive amounts of data in a cloud-native architecture. Threat hunting is defined as the hypothesis-driven exploration of an enterprise's environ ment to detect and isolate undiscovered malicious activity. The process relies on advanced knowledge of attackers and their techniques to create detection-focused intelligence that is then fed back into observability solutions. Conducting efficacious threat hunting involves defining clear objectives; selecting appropriate data sources, collection pipelines, and storage solutions; and developing detection capabilities that specifically target areas of interest. Despite the widespread adoption of threat hunting in traditional enterprise networks, cloud operating models introduce significant new characteristics and considerations that warrant development of a corresponding enterprise cloud threat-hunting framework.Abstract
Overreliance on signature-based sensor data, automation, and information sharing often enables threat actors to perpetrate cyberattacks such as ransomware, cryptojacking, and other undetected activities for months. Even without prior knowledge of an attack, security teams have the opportunity to locate advanced persistent threats that have already evaded existing security controls. Organizations must thus embrace threat hunting—proactively seeking active adversaries in their environments using tailored detection capabilities. Information technology teams operating in public cloud environments can now empower hunting by observing attack paths, developing detection capabilities in a serverless, on-demand, and cost-effective manner, and storing massive amounts of data in a cloud-native architecture.
Threat hunting is defined as the hypothesis-driven exploration of an enterprise's environ ment to detect and isolate undiscovered malicious activity. The process relies on advanced knowledge of attackers and their techniques to create detection-focused intelligence that is then fed back into observability solutions. Conducting efficacious threat hunting involves defining clear objectives; selecting appropriate data sources, collection pipelines, and storage solutions; and developing detection capabilities that specifically target areas of interest. Despite the widespread adoption of threat hunting in traditional enterprise networks, cloud operating models introduce significant new characteristics and considerations that warrant development of a corresponding enterprise cloud threat-hunting framework.
References
[1]Digital Threat Lifecycle. (2020). The Digital Threat Lifecycle: A Disruptive Strategy for Building Intelligence-Driven Cyber Defence. Retrieved on 2020-08-25 from [Link]
[2]Ahlgren, B., & Lindgren, P. (2013). Cyber Security Exercise as a Knowledge Management Tool – Conceptual Design. 28th International Conference on Information Networking (ICOIN) (pp. 273–278). IEEE. doi:10.1109/ICOIN.2014.6799840.
[3]Almach, A., & Alzubi, A.D. (2021). Intelligence in Cybersecurity: What, Why and How? IEEE Access, 9, 126837–126866. doi:10.1109/ACCESS.2021.3119787.
[4]Alzubaidi, L., Hussain, B., Zhang, J., Fadhl, A.A., & Konovalov, S. (2020). Threat Hunting Framework into Cloud-Native Environments: A Deployment Architecture Based on a Threat Intelligence Strategy. Future Generation Computer Systems, 108, 221–235. doi:10.1016/j.future.2020.01.012.
[5]Anisi, M.H., & Sukkarieh, S. (2022). Industry 4.0 Cyber Physics Security Framework. World Journal of Engineering, 19(6), 1–12. doi:10.1108/WJE-06-2021-0364.
[6]Arshad, S.Z., Alghamdi, S.S.M., Alharbi, F.A., Alshehri, H.M., & Aldawood, A. (2021). Cyber Security Risk Management Framework in Health Care Sector Based on CSF Guidelines. IEEE Access, 9, 109013–109022. doi:10.1109/ACCESS.2021.3117393.
[7]Ashiq, H.E., Wang, H., Mohsin, S., & Ding, H. (2021). A Hybrid Defense Mechanism for Mitigating DDoS Attacks in the Malware as a Service Model. IEEE Access, 9, 89156–89169. doi:10.1109/ACCESS.2021.3080367.
[8]Chaim, M.D., & Hsu, C.Y. (2021). A Novel Cybersecurity Framework for Enhancing Application Security against SQL Injection Attacks. IEEE Access, 9, 83311–83321. doi:10.1109/ACCESS.2021.3083489.
[9]Mahboubi, A., Luong, K., Aboutorab, H., Bui, H. T., & Jarrad, G. (2024). Evolving techniques in cyber threat hunting: A systematic review. Journal of Network and Computer Applications.
[10]Varma, S. C. G. (2024). AI-enhanced cloud security: Proactive threat detection and response mechanisms. International Journal of Cloud Computing.
[11]Alanezi, M. (2024). AI-powered cyber threats: A systematic review. Journal of Cybersecurity Research.
[12]Schwartz, Y., Benshimol, L., Mimran, D., Elovici, Y., & Shabtai, A. (2024). LLMCloudHunter: Harnessing large language models for automated cloud threat intelligence extraction. IEEE Access.
[13]Rahmati, M.Explainable and lightweight AI for real-time cyber threat hunting in edge networks. IEEE Internet of Things Journal.
[14]Roy, S. AgenticCyber: A generative AI-powered multi-agent framework for adaptive cybersecurity threat detection. ACM Transactions on Privacy and Security.
[15]Abdiukov, T. AI-powered threat hunting: Designing real-time predictive security frameworks for cloud environments. Global Journal of Engineering and Technology Advances.
[16]Singh, R., Kumar, P., & Sharma, S. (2024). Intelligent cloud security frameworks using deep learning for cyber threat detection. IEEE Transactions on Cloud Computing.
Additional Files
Published
Data Availability Statement
None