Design of an Efficient Model for Enhancing Cloud Security Using Temporal Fusion Transformers and Deep Reinforcement Learning

Main Article Content

Kavita A.Kathane, Dr.Virendra K. Sharma

Abstract

The ever-increasing complexity and dynamism of cloud environments call for advanced forensics mechanisms that can enable proactive security threat detection and have to make up for some of the limitations of traditional static security systems. In most cases, these methods typically have a high false positive rate and slow detection time, and in such cases, they are undesirable since they cannot keep pace with changing data streams and intricate patterns of emerging threats. In this paper, a novel Recommendation-based Cloud Forensics framework has been proposed. It consists of a Temporal Fusion Transformer (TFT) for the generation of dynamic, context-specific security recommendations and a Deep Reinforcement Learning for Dynamic Alert Threshold Adjustment mechanism for real-time alerting. The TFT method excels in handling multi-modal time-series data such as logs, system metrics, network traffic, and user behavior, but with its strengths in this area, the TFT is particularly apt at modeling the complex temporal dependencies of sequential data. The Transformer architecture, combined with a temporal fusion mechanism, will increase the accuracy and relevance of such security recommendations. Such recommendations are informed by a rich dataset covering both current system states and historical security events. Preliminary results from the TFT show that it can potentially decrease false positives by 20% and increase the detection speed of security events by 15%. In addition, DRL-DATA dynamically adjusts the thresholds for alerting based on perceived security risks, using the interaction of a reinforcement learning agent to learn optimal alerting policies from the interaction with the cloud environment. By intelligently balancing the tradeoff between false positives and false negatives, the DRL-DATA method aims to reduce false alarm rates by 25% while maintaining or improving detection rates. These methods form a strong framework that resolves some of the existing limitations of static, non-adaptive security systems and provides an adaptability and precision previously unattainable. Integration of TFT and DRL-DATA marks a huge leap forward toward cloud forensics and may revolutionize the ways in which security events are predicted, detected, and managed in a cloud environment. This framework guarantees immense impacts in improving the security posture of cloud services, eventually leading to more resilient cloud infrastructures & scenarios.


 

Article Details

Section
Articles