Runtime Threat Detection in Serverless Architectures Using Behavioral Monitoring Models

Authors

  • Mohammed Rafique Senior Solution Architect, AgreeYa Solutions Inc, Texas, USA Author
  • Lekhya Sake Quality Analyst, Boom Interactive, Houston, Texas, USA Author
  • Oli Wood Research Scientist, University of Helsinki, Helsinki, Finland Author

Abstract

Serverless computing has transformed cloud computing with dynamic resource allocation, cost savings, and operational ease. Ephemeral execution contexts, function-level isolation limitations, and ineffective intrusion detection methods arise from infrastructure abstraction. Most systems utilize static analysis or coarse-grained monitoring, which overlook runtime irregularities that suggest sophisticated persistent threats, privilege escalation, or code injection assaults in ephemeral routines. The serverless runtime behavioral monitoring system in this work uses function-level activity profiling, anomaly detection models, and contextual behavioral baselines. Abnormal function behaviors are identified using real-time telemetry, adaptive thresholding, and multi-dimensional execution metrics. Formalizing function-level behavioral fingerprints, constructing predictive anomaly detection algorithms, and outperforming current methods in detection accuracy and false-positive rates are major contributions. This affects serverless deployment security, cloud-native intrusion detection, and behavioral analytics integration into automated serverless security orchestration.

Downloads

Download data is not yet available.

Downloads

Published

17-05-2022

How to Cite

[1]
M. Rafique, L. Sake, and O. Wood, “Runtime Threat Detection in Serverless Architectures Using Behavioral Monitoring Models”, J. Artif. Intell. Mach. Learn. Stud., vol. 6, pp. 182–200, May 2022, Accessed: Jul. 28, 2026. [Online]. Available: https://jaimls.org/index.php/publication/article/view/53