Serverless Guardian: An Integrated Intrusion Detection and Automated Response Framework for Cloud-Native Security

Main Article Content

Jon Garcia

Abstract

Serverless computing platforms such as AWS Lambda have revolutionized cloud application design by enabling stateless, event-driven architectures with automatic scaling and fine-grained billing. However, the ephemeral and opaque nature of these environments poses significant challenges for traditional intrusion detection systems, which are often incompatible with transient execution flows and lack fine-grained observability [1]. This paper presents SageShield-SOAR, a comprehensive serverless-aware intrusion detection and automated response framework that extends the SageShield detection engine [1] with Security Orchestration, Automation, and Response (SOAR) capabilities [2], [3]. The framework combines cold-start-aware telemetry modeling, transformer-based embedding of execution traces, probabilistic anomaly detection using hybrid density estimation techniques, and a serverless SOAR pipeline for automated incident response [1], [4]. The system integrates seamlessly with AWS services including CloudWatch, X-Ray, Step Functions, GuardDuty, EventBridge, Lambda, and SQS to provide real-time alerts and policy-driven mitigation without interfering with business logic [1], [5]. Building upon the cyber defense system framework of Mistry et al. [6], SageShield-SOAR implements a case-based threat scoring mechanism where related events are aggregated into cases, threat scores are dynamically updated, and significance conditions trigger automated response actions [6]. The framework also incorporates the automated anomaly detection and response system described in the Mistry patent [7], which provides contextual analysis and adaptive response capabilities for cloud security. Extensive experiments on synthetic and real-world Lambda workloads demonstrate that SageShield achieves a detection accuracy of 96.2%, maintains a low false positive rate of 2.8%, and introduces less than 3.1% runtime overhead [1]. 

Article Details

How to Cite
Jon Garcia. (2025). Serverless Guardian: An Integrated Intrusion Detection and Automated Response Framework for Cloud-Native Security. Journal of Quantum Science and Technology, 2(1), Jan (923–939). https://doi.org/10.63345/jqst.v2i1.434
Section
Original Research Articles

References

R. K. Kripa, "SageShield: A Serverless-Aware Intrusion Detection and Response Framework for AWS Lambda Ecosystems," in IEEE International Conference on Computing, Communication, and Intelligent Systems, Indore, India, 2024.

Cookpad, "DeepAlert: Serverless SOAR Framework for Automatic Inspection and Evaluation of Security Alerts," GitHub Repository, 2024.

H. K. Mistry, A. M. Goswami, and C. C. Mavani, "Automated Anomaly Detection and Response System for Enhancing Cloud Security," Indian Patent Application, July 2024.

thtcsec, "AWS-Serverless-SOAR: Automated Serverless Security Orchestration, Automation, and Response Platform," GitHub Repository, 2023.

"Web Application Security System with Automated Recovery and Threat Mitigation," in IEEE International Conference on Computing, Communication, and Intelligent Systems, 2025.

J. Mistry and D. Atkinson, "Cyber Defense System," US Patent 11,516,233 B2, Nov. 29, 2022.

H. K. Mistry, A. M. Goswami, and C. C. Mavani, "Automated Anomaly Detection and Response System for Enhancing Cloud Security," Indian Patent Application, July 2024.

Gartner, "Market Guide for Serverless Computing Platforms," Gartner Report, 2024.

Baldini, P. Castro, K. Chang et al., "Serverless computing: Current trends and open problems," Research Advances in Cloud Computing, 2017.

C. Kruegel and G. Vigna, "Anomaly detection of web-based attacks," in Proceedings of the 10th ACM Conference on Computer and Communications Security (CCS), 2003.

W. Li, R. Wu, X. Du, and X. Wang, "Understanding the security implications of the AWS Lambda ecosystem," in Proceedings of the 30th USENIX Security Symposium, 2021.

O. Tripp, M. Shah, and A. Singh, "Cloudless threats: Attack vectors in ephemeral serverless systems," ACM Transactions on Privacy and Security (TOPS), 2023.

Y. Wang, R. Duan, and F. Yu, "Securing serverless computing using function-level monitoring and profiling," in Proceedings of the ACM Asia Conference on Computer and Communications Security (AsiaCCS), 2020.

E. Lee, J. Kim, and S. Park, "Telemetry-guided profiling for cloud-native serverless platforms," IEEE Transactions on Cloud Computing, 2021.

Y. Liu, M. Zhang, and L. Tan, "Lightweight model compression for serverless edge security," Proceedings of the ACM on Measurement and Analysis of Computing Systems (POMACS), 2022.

S. Eismann, J. Scheuner, N. Herbst, and S. Kounev, "A review of serverless use cases and their characteristics," Journal of Systems and Software, vol. 181, p. 111038, 2021.

L. Wang, M. Li, Y. Zhang, T. Ristenpart, and M. Swift, "Peeking behind the curtains of serverless platforms," in Proceedings of the 2018 USENIX Annual Technical Conference (ATC), 2018.

T. Garfinkel and M. Rosenblum, "Virtual machine introspection for intrusion detection," ACM SIGOPS Operating Systems Review, vol. 37, pp. 191-206, 2003.

M. Armbrust, A. Fox, R. Griffith et al., "A view of cloud computing," Communications of the ACM, vol. 53, no. 4, pp. 50-58, 2010.

P. Castro, V. Ishakian, V. Muthusamy, and A. Slominski, "Serverless programming for the cloud," IEEE Internet Computing, vol. 22, no. 5, pp. 12-19, 2018.

AWS, "AWS Lambda: Serverless Compute," AWS Documentation, 2024.

N. C. Zakaria, H. F. L. Y. C. K. T. Lin, and N. F. M. Azmi, "Security challenges in serverless computing: A systematic literature review," IEEE Access, vol. 11, pp. 345-360, 2023.

M. S. Ali, "Serverless security: Challenges and solutions," Journal of Cloud Computing, vol. 12, no. 1, 2023.

J. M. Hellerstein, J. Faleiro, J. Gonzalez et al., "Serverless computing: One step forward, two steps back," arXiv preprint arXiv:1812.03651, 2018.

T. Lynn, P. Rosati, A. Lejeune, and V. Emeakaroha, "A preliminary review of enterprise serverless cloud computing (Function-as-a-Service) platforms," in Proceedings of the IEEE International Conference on Cloud Computing Technology and Science (CloudCom), 2017.

A. L. Buczak and E. Guven, "A survey of data mining and machine learning methods for cyber security intrusion detection," IEEE Communications Surveys & Tutorials, vol. 18, no. 2, pp. 1153-1176, 2015.

K. Shaukat et al., "A survey on machine learning techniques for cyber security in the last decade," IEEE Access, vol. 8, pp. 222310-222354, 2020.

H. Sarker et al., "Cybersecurity data science: an overview from machine learning perspective," Journal of Big Data, vol. 7, pp. 1-29, 2020.

F. Kilincer, F. Ertam, and A. Sengur, "Machine learning methods for cyber security intrusion detection: Datasets and comparative study," Computer Networks, vol. 188, 107840, 2021.

A. Vaswani, N. Shazeer, N. Parmar et al., "Attention is all you need," in Advances in Neural Information Processing Systems, vol. 30, 2017.

N. J. A. B. Leite, "SOAR: Security Orchestration, Automation, and Response," IEEE Security & Privacy, vol. 19, no. 3, pp. 67-72, 2021.

S. Burkart, D. Lang, and S. Bittner, "Federated anomaly detection for serverless architectures in multi-cloud environments," IEEE Transactions on Cloud Computing, 2023.

A. Kurakin, I. Goodfellow, and S. Bengio, "Adversarial machine learning at scale," arXiv preprint arXiv:1611.01236, 2016.

Lu, A. Liu, F. Dong, F. Gu, J. Gama, and G. Zhang, "Learning under concept drift: A review," IEEE Transactions on Knowledge and Data Engineering, vol. 31, no. 12, pp. 2346-2363, 2019.

Similar Articles

<< < 3 4 5 6 7 8 9 10 11 12 > >> 

You may also start an advanced similarity search for this article.