AI-Driven Causal Inference for Cross-Cloud Threat Detection Using Anonymized CloudTrail Logs

Jay Barach · 2025

This paper presents an AI-driven framework for anomaly detection and predictive security modeling in multi-cloud environments, addressing the complexity of modern cloud infrastructures. It uses AWS CloudTrail logs to track user activities, API calls, and network events. By integrating machine learning models like Autoencoders and LSTM networks, it achieves a 96% detection accuracy with a 4% false positive rate, improving on existing methods. Key innovations include cross-cloud threat correlation, detecting coordinated attacks across providers like AWS, Azure, and Google Cloud, using a custom correlation function. The framework also excels in proactive threat detection, achieving 91% accuracy in forecasting security incidents, helping anticipate and mitigate risks. Real-Time data processing through Apache Kafka allows efficient log streaming, and GPU-accelerated training in Google Colab ensures effective operation in large environments. It boasts a Mean Time to Detect (MTTD) of 28 seconds and a Mean Time to Resolve (MTTR) of 18 minutes.

Read the paper · More papers on PaperTik