AI-Driven Incident Response Using Collaborative Cyber Security Analytics for Enterprise Cloud Environments

Main Article Content

Alex Mathew

Abstract

Modern enterprise cloud environments face increasingly sophisticated, multi-vector cyberattacks that easily bypass traditional perimeter-based defenses and isolated Security Information and Event Management (SIEM) platforms. The velocity and scale of cloud-native threats necessitate an evolution from manual, siloed threat detection toward automated, intelligence-driven mitigation architectures. This paper proposes a comprehensive, privacy-preserving framework titled "AI-Driven Incident Response Using Collaborative Cyber Security Analytics for Enterprise Cloud Environments." By combining federated learning paradigms, graph neural networks (GNNs), and automated orchestration engines, the framework aggregates threat intelligence across heterogeneous, multi-tenant cloud ecosystems without exposing sensitive proprietary logs. The architecture constructs dynamic attack-path graphs from multi-source telemetry, uses spatial-temporal neural models to detect lateral movement and zero-day exploits, and deploys deep reinforcement learning agents to execute real-time containment protocols. Empirical evaluations on multi-cloud benchmark environments demonstrate that this collaborative framework reduces Mean Time to Detect (MTTD) by 64%, accelerates Mean Time to Respond (MTTR) by 78%, and decreases false-positive alerts by 41% compared to traditional centralized security operational frameworks. Ultimately, this research provides a scalable, privacy-conscious blueprint for autonomous cloud security operations, enabling collective defense capabilities across distributed enterprise cloud infrastructures.

 

Article Details

Section

Articles

How to Cite

AI-Driven Incident Response Using Collaborative Cyber Security Analytics for Enterprise Cloud Environments. (2026). International Journal of Research Publications in Engineering, Technology and Management (IJRPETM), 9(2), 676-683. https://doi.org/10.15662/IJRPETM.2026.0902023

References

1. Mell, P., & Grance, T. (2011). The NIST definition of cloud computing (Special Publication 800-145). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-145

2. Shiravi, A., Shiravi, H., Tavallaee, M., & Ghorbani, A. A. (2012). Toward developing a systematic digital forensics investigation framework for cloud computing. Computers & Security, 31(7), 805–824. https://doi.org/10.1016/j.cose.2012.06.008

3. Modi, C., Patel, D., Borisaniya, B., Patel, H., Patel, A., & Rajarajan, M. (2013). A survey of intrusion detection techniques in cloud. Journal of Network and Computer Applications, 36(1), 42–57. https://doi.org/10.1016/j.jnca.2012.08.003

4. McMahan, B., Moore, E., Ramage, D., Hampson, S., & y Arcas, B. A. (2017). Communication-efficient learning of deep networks from decentralized data. Proceedings of the 20th International Conference on Artificial Intelligence and Statistics (AISTATS), 1273–1282.

5. Chiba, Z., Abghour, N., Moussaid, K., El Aroussi, M., & Rida, M. (2019). New anomaly network intrusion detection system in cloud environment using complex machine learning algorithms. Journal of Big Data, 6(1), 1–29. https://doi.org/10.1186/s40537-019-0211-1

6. Rabbani, M., Wang, Y. L., Khoshkangini, R., Jelodar, H., & Zhao, R. (2020). A hybrid machine learning framework for cyber threat intelligence and incident response in cloud environments. IEEE Transactions on Cloud Computing, 10(3), 1845–1857. https://doi.org/10.1109/TCC.2020.2984512

7. Sahoo, K. S., Tiwary, M., Sahoo, S., Sahoo, B., & Dash, R. (2020). Deep-reinforcement-learning-based automated incident response framework for software-defined cloud networks. IEEE Systems Journal, 15(2), 2310–2318. https://doi.org/10.1109/JSYST.2020.2998782

8. Tiwari, S., Guruswamy, M., Gandhi, S. T., Singh, S., & Huang, K. (2026). U.S. Patent No. 12,566,844. Washington, DC: U.S. Patent and Trademark Office.

9. Al-Ibrahim, M., & Al-Khader, W. (2021). Collaborative cyber threat intelligence sharing using blockchain and federated learning in multi-cloud environments. IEEE Access, 9, 145210–145224. https://doi.org/10.1109/ACCESS.2021.3121890

10. Kumar, P., Gupta, G. P., & Tripathi, R. (2021). An ensemble learning and fog-cloud architecture-driven cyber-attack detection framework for IoMT networks. Computer Communications, 166, 110–124. https://doi.org/10.1016/j.comcom.2020.12.003

11. Zhang, X., Chen, Y., Lin, X., & Wang, H. (2021). Graph neural networks for cybersecurity: A comprehensive survey. IEEE Transactions on Knowledge and Data Engineering, 34(11), 5120–5138. https://doi.org/10.1109/TKDE.2021.3061298

12. Tuli, S., Basumatary, A., & Buyya, R. (2022). EdgeAI-Sec: Autonomous threat detection and incident response in edge-cloud infrastructures using deep reinforcement learning. Future Generation Computer Systems, 135, 162–175. https://doi.org/10.1016/j.future.2022.04.028

13. Li, J., Zhao, Z., & Gao, R. (2022). Privacy-preserving collaborative cyber threat detection using differential privacy and federated learning. Computers & Security, 118, 102731. https://doi.org/10.1016/j.cose.2022.102731

14. Al-Hawawreh, M., & Sitnikova, E. (2023). A cyber-resilient framework for threat intelligence and automated incident response in cloud-native microservices. Journal of Information Security and Applications, 72, 103390. https://doi.org/10.1016/j.jisa.2022.103390

15. Varma, S. C. G. (2024). AI-enhanced cloud security: Proactive threat detection and response mechanisms. International Journal of Computer Science and Network Security, 24(3), 112–125.

16. Sunarjo, R. A. (2025). AI enabled cybersecurity framework for multi cloud business environments. ADI Journal on Recent Innovation, 7(1), 45–58. https://doi.org/10.34306/ajri.v7i1.1312