Edge-Based Policy Caching for Low Latency Security Enforcement in Hybrid Clouds

Geonmin Kim, Yejin Kim, Eunseong Lee, Hyeonji Jang, Kyungbaek Kim · 2025

With the spread of big data and the development of cloud computing technology, many enterprises are switching to a hybrid-cloud environment that combines on-premises infrastructure and public and private clouds. However, this integration of heterogeneous infrastructures reveals the limitations of existing boundary-based security models and exposes policy-evaluation latency. In particular, delays in evaluating and applying security policies across infrastructures create bottlenecks in real-time detection and response systems. Recently, new security approaches based on artificial intelligence and generative AI have been proposed for modern hybrid-cloud architectures. Therefore, this study proposes a hybrid-cloud security model that integrates machine learningbased anomaly detection, real-time log analysis, automatic policy generation, and policy caching to the edge. The proposed model comprises a traffic gateway layer that centralizes and collects API request metadata, a policy generation layer that repeatedly trains log data from collected requests and generates new policies, and a policy evaluation layer that minimizes response delay by using edge and central policy agents in a dual configuration. This model introduces the concept of risk-aware security policy caching, which blocks high-frequency attacks at the edge while simultaneously improving detection rate and response speed. Through this, major performance indicators such as anomaly detection accuracy and policy application delay time were quantitatively evaluated. Over 10 iterative experimental rounds, the proposed model achieved an average attack detection rate of $\mathbf{8 9. 7 5 \%}$ outperforming the centralized base model at $85.91 \%$ while reducing the block time of attack logs by $20.07 \%$ through policy caching.

Read the paper · More papers on PaperTik