Autonomous LLM-Driven Anomaly Detection and Self-Healing Response Framework for Multi-Cloud Security
Keywords:
Abstract
The proliferation of multi-cloud architectures has significantly expanded the cyber-attack surface, rendering traditional, reactive security measures inadequate. Current security information and event management (SIEM) systems often struggle with high false-positive rates and manual, time-consuming investigation processes, which are further exacerbated by the complexity and heterogeneity of multi-cloud environments. This paper proposes a novel framework that leverages Large Language Models (LLMs) to achieve autonomous anomaly detection and self-healing security responses across disparate cloud service providers. The framework utilizes LLMs to analyze multi-source telemetry data contextually, moving beyond simple rule-based or statistical anomaly detection to understand attack intent and generate automated, adaptive remediation playbooks.
Our proposed framework integrates a modular data ingestion layer that unifies security telemetry from major cloud providers like AWS, Azure, and Google Cloud. A core LLM engine analyzes aggregated data to identify subtle anomalies that evade conventional systems, providing root-cause analysis and prioritizing threats based on potential business impact. Crucially, the system features a self-healing decision engine that autonomously generates and executes precisely targeted responses—such as isolation of compromised instances, automated credential rotation, and firewall rule updates—while maintaining a continuous learning loop to refine its capabilities and reduce false positives over time. This approach aims to reduce mean time to detect (MTTD) and mean time to respond (MTTR), achieving a near-instantaneous, automated defense posture.
Downloads
Published
How to Cite
Issue
Section
License

This work is licensed under a Creative Commons Attribution-NoDerivatives 4.0 International License.