EventsThe 6th International Electronic Conference on Applied Sciences
Published
This submission belongs to the session S3. Computing and Artificial Intelligence of the event The 6th International Electronic Conference on Applied Sciences
Published date
03 Dec, 2025
Academic Editor
author-avatarLucia Billeci
Citation
Antonina Ivanova, Teodora Bakardjieva, Anton Chagovec, Veselina Spasova, Andriana Ivanova, Fatima Sapundzhi, AI‑Driven Threat Detection and Automated Incident Response for Securing Cloud Workloads, in Proceedings of The 6th International Electronic Conference on Applied Sciences, 9 December–11 December 2025, MDPI: Basel, Switzerland
Share
Email
Facebook
Twitter
LinkedIn

AI‑Driven Threat Detection and Automated Incident Response for Securing Cloud Workloads

image
image
Veselina Spasova 1,3
1. Department of Computer Science, Faculty of Social, Business and Computer Sciences, Varna Free University “Chernorizets Hrabar”, 84 Yanko Slavchev Str., Chaika Resort, 9007 Varna, Bulgaria, Bulgaria
2. Department of Communication and Computer Engineering, Faculty of Engineering, South-West University “Neofit Rilski”, 66 Ivan Myhailov Str., 2700 Blagoevgrad, Bulgaria, Bulgaria
3. Department of Informational and Communication Technology, Faculty of Engineering, Nikola Vaptsarov Naval Academy, 73 Vasil Drumev, 9002, Varna, Bulgaria
Abstract

Escalating cloud adoption has multiplied organisations’ digital footprints—and their exposure to credential abuse, misconfiguration, and ransomware. This study examines how artificial intelligence (AI) analytics embedded in next‑generation Security Information and Event Management (SIEM) and Extended Detection and Response (XDR) platforms can fortify cloud defences while relieving Security Operations Centre (SOC) fatigue.

An extensive literature review was combined with an empirical evaluation in a production‑like enterprise cloud environment that fused a modern, data‑lake‑based SIEM, a vendor‑agnostic XDR layer, and a generative‑AI assistant orchestrating automated playbooks. Three realistic attack chains—phishing‑led account takeover, multi‑stage ransomware, and shadow‑IT data exfiltration—were replayed. Key metrics captured were mean time‑to‑detect/‑respond (MTTD/MTTR), incident‑correlation precision, and false‑positive rate.

AI‑assisted correlation collapsed hundreds of raw alerts into single contextual incidents, cutting analyst triage time by 96 %. Behaviour‑profiling models in the XDR layer reduced false positives by 89 %, while automated, AI‑guided playbooks contained live ransomware in under five minutes—an 18‑fold improvement over manual response. Overall, AI integration shortened MTTD and MTTR from hours to minutes across all scenarios.

The findings demonstrate that AI‑enabled SIEM/XDR can transform cloud security from reactive monitoring to proactive, autonomous defence, simultaneously boosting protection and SOC efficiency. Future work will explore reinforcement‑learning agents for dynamic policy tuning and assess interoperability among heterogeneous XDR components in complex multi‑cloud environments.

Keywords
Artificial intelligence
Cloud computing security
Threat detection
Automated incident response
Security Information and Event Management (SIEM)
Extended Detection and Response (XDR)
Security Operations Centre (SOC)
Ransomware attacks
Deep Learning and Transfer Learning Models of Indian Food Classification
Undaria Pinnatifida as a Biofuel Feedstock: Challenges and Opportunities