Transforming Cybersecurity with AI-driven Dashboards: A Cloud-Native Implementation Framework for Real-Time Threat Detection and Automated Response
Abstract
Enterprise migration to hybrid and multi-cloud environments has exponentially expanded the attack surface, rendering traditional Security Operations Center workflows - built on rule-based Security Information and Event Management correlation - structurally inadequate for the detection velocity, alert volume, and behavioral threat complexity of modern cloud-native threat landscapes. This paper proposes a four-layer Artificial Intelligence–Driven Cybersecurity Dashboard architecture integrating cloud-native logging aggregation, stream processing, machine learning threat classification, and automated orchestration. A simulation-based evaluation is conducted across a representative enterprise environment comprising two cloud providers, 500 virtual machines, and 2,000 users with injected threat scenarios spanning identity privilege escalation, lateral movement, and application programming interface abuse. Post-deployment simulation results demonstrate a 63% reduction in mean time to respond, a 71% improvement in mean time to detect, and a 48.8% reduction in false positive alert rate, with automated response handling 52% of incidents without human analyst intervention. The framework provides a phased deployment roadmap, mathematical risk scoring formulation, and compliance mapping architecture enabling Security Operations Centers to transition from reactive rule-based monitoring to adaptive, continuously learning artificial intelligence–driven operations.
Article Information
Journal |
International Journal of Future Innovative Science and Technology (IJFIST) |
|---|---|
Volume (Issue) |
Vol. 5 No. 5 (2022): International Journal of Future Innovative Science and Technology (IJFIST) |
DOI |
|
Pages |
9207-9217 |
Published |
October 8, 2022 |
| Copyright |
All rights reserved |
Open Access |
This work is licensed under a Creative Commons Attribution 4.0 International License. |
How to Cite |
Sivaramakrishnan Narayanan (2022). Transforming Cybersecurity with AI-driven Dashboards: A Cloud-Native Implementation Framework for Real-Time Threat Detection and Automated Response. International Journal of Future Innovative Science and Technology (IJFIST) , Vol. 5 No. 5 (2022): International Journal of Future Innovative Science and Technology (IJFIST) , pp. 9207-9217. https://doi.org/10.15662/IJFIST.2022.0505004 |
References
2. Veerasamy, N., & Grobler, M. (2019). A cybersecurity incident response and management framework for connected environments. Journal of Information Warfare, 18(2), 14–27. https://www.jinfowar.com
3. Kamadi, S. (2021). Risk exception management in multi-regulatory environments: A framework for financial services utilizing multi-cloud technologies. Paperpile.
4. Nguyen, T. T., & Reddi, V. J. (2021). Deep reinforcement learning for cyber security. IEEE Transactions on Neural Networks and Learning Systems, 34(8), 3779–3795. https://doi.org/10.1109/TNNLS.2021.3121870
5. Gavai, G., Sricharan, K., Gunning, D., Hanley, J., Singhal, M., & Rolleston, R. (2015). Supervised and unsupervised methods to detect insider threat from enterprise social and online activity data. Journal of Wireless Mobile Networks, Ubiquitous Computing, and Dependable Applications, 6(4), 47–63. https://doi.org/10.22667/JOWUA.2015.12.31.047
6. Souppaya, M., & Scarfone, K. (2018). Guide to enterprise patch management technologies (NIST Special Publication 800-40 Rev. 3). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-40r3
7. Mirsky, Y., Doitshman, T., Elovici, Y., & Shabtai, A. (2018). Kitsune: An ensemble of autoencoders for online network intrusion detection. Proceedings of the Network and Distributed System Security Symposium. https://doi.org/10.14722/ndss.2018.23204
8. Buczak, A. L., & Guven, E. (2017). A survey of data mining and machine learning methods for cyber security intrusion detection. IEEE Communications Surveys and Tutorials, 18(2), 1153–1176. https://doi.org/10.1109/COMST.2015.2494502
9. Dixit, P., & Silakari, S. (2021). Deep learning algorithms for cybersecurity applications: A technological and status review. Computer Science Review, 39, 100317. https://doi.org/10.1016/j.cosrev.2020.100317
10. Brundage, M., Avin, S., Clark, J., Toner, H., Eckersley, P., Garfinkel, B., Dafoe, A., Scharre, P., Zeitzoff, T., Filar, B., Anderson, H., Roff, H., Allen, G. C., Steinhardt, J., Flynn, C., Héigeartaigh, S., Beard, S., Belfield, H., Farquhar, S., & Amodei, D. (2018). The malicious use of artificial intelligence: Forecasting, prevention, and mitigation. Future of Humanity Institute. https://arxiv.org/abs/1802.07228
11. Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero trust architecture (NIST Special Publication 800-207). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-207
12. National Institute of Standards and Technology. (2018). Framework for improving critical infrastructure cybersecurity (Version 1.1). U.S. Department of Commerce. https://doi.org/10.6028/NIST.CSWP.04162018
13. McMahan, B., Moore, E., Ramage, D., Hampson, S., & Agüera y Arcas, B. (2017). Communication-efficient learning of deep networks from decentralized data. Proceedings of the 20th International Conference on Artificial Intelligence and Statistics, 54, 1273–1282. https://proceedings.mlr.press/v54/mcmahan17a.html
14. Leike, J., Martic, M., Krakovna, V., Ortega, P. A., Everitt, T., Lefrancq, A., Orseau, L., & Legg, S. (2018). AI safety gridworlds. arXiv preprint. https://arxiv.org/abs/1711.09883
15. Devlin, J., Chang, M. W., Lee, K., & Toutanova, K. (2019). BERT: Pre-training of deep bidirectional transformers for language understanding. Proceedings of the North American Chapter of the Association for Computational Linguistics, 4171–4186. https://doi.org/10.18653/v1/N19-1423
16. Papernot, N., McDaniel, P., Goodfellow, I., Jha, S., Celik, Z. B., & Swami, A. (2017). Practical black-box attacks against machine learning. Proceedings of the ACM Asia Conference on Computer and Communications Security, 506–519. https://doi.org/10.1145/3052973.3053009