A rule-driven SOC architecture for real-time threat detection and autonomous incident response
DOI:
https://doi.org/10.18488/76.v13i3.5150Keywords:
Cloud security telemetry, Incident response automation, MITRE ATT&CK, Rule-based security analytics, Security operations center, Threat detection.Abstract
Security Operations Centers (SOCs) are essential for monitoring and responding to cyber threats in cloud-native environments, where infrastructure is dynamic, multi-tenant, and API-driven. Conventional SOCs rely heavily on manual triage and SIEM-based alerting, resulting in delayed detection of cloud-specific attacks such as IAM misuse, privilege escalation, and data exfiltration. This paper proposes a rule-driven SOC architecture that integrates cloud telemetry, threat intelligence, MITRE ATT&CK Cloud Matrix mappings, and SOAR-based response automation. The framework normalizes heterogeneous logs, correlates multi-stage attack behaviors, enriches alerts with threat intelligence, and executes automated or semi-automated remediation actions. Evaluation using AWS CloudTrail, VPC Flow Logs, Azure Activity Logs, and Kubernetes audit logs demonstrates a 41.2% reduction in time-to-detection, a 37.5% reduction in time-to-response, and 87.9% precision in automated remediation.
