Runtime Threat Detection in Serverless Architectures Using Behavioral Monitoring Models
Abstract
Serverless computing has transformed cloud computing with dynamic resource allocation, cost savings, and operational ease. Ephemeral execution contexts, function-level isolation limitations, and ineffective intrusion detection methods arise from infrastructure abstraction. Most systems utilize static analysis or coarse-grained monitoring, which overlook runtime irregularities that suggest sophisticated persistent threats, privilege escalation, or code injection assaults in ephemeral routines. The serverless runtime behavioral monitoring system in this work uses function-level activity profiling, anomaly detection models, and contextual behavioral baselines. Abnormal function behaviors are identified using real-time telemetry, adaptive thresholding, and multi-dimensional execution metrics. Formalizing function-level behavioral fingerprints, constructing predictive anomaly detection algorithms, and outperforming current methods in detection accuracy and false-positive rates are major contributions. This affects serverless deployment security, cloud-native intrusion detection, and behavioral analytics integration into automated serverless security orchestration.
Downloads
Downloads
Published
Issue
Section
License
Copyright (c) 2022 Mohammed Rafique, Lekhya Sake, Oli Wood (Author)

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.