Adaptive SOAR Using Deep Reinforcement Learning for Autonomous Threat Detection in Cloud-Native Architectures

Authors

  • Radhika Kande Sagarsoft Inc, USA
  • Chaithanya Kotla Devops and Cloud lead, State of Maryland, USA
  • Krishna kanth Thottempudi Hermes Networks Inc, USA
  • Pradeep Anjuru Systems Technology group, USA
  • Sivaprakash Nithyanandam Systems Technology group, USA

Keywords:

Adaptive SOAR, deep reinforcement learning, cloud-native security, autonomous mitigation, threat detection, incident prioritization, service disruption control.

Abstract

Cloud-native threat response requires more than predefined SOAR playbooks because attacks can shift across workloads, identities, APIs, network paths, and runtime policies within short operational windows. This article develops an adaptive SOAR framework that uses deep reinforcement learning to improve autonomous threat detection, incident prioritization, and mitigation selection in cloud-native architectures. The framework converts alert severity, anomaly scores, workload identity, asset criticality, exploitability, service dependency, and post-action telemetry into reinforcement learning states, while response actions include alert suppression, traffic throttling, workload isolation, credential revocation, rerouting, rollback, and analyst escalation. The grouped-bar results show that threat detection accuracy, prioritization precision, and mitigation success improve across training phases, while the radar-based severity analysis shows stronger response time reduction, controlled false positive suppression, and stable service disruption control. The study concludes that DRL-based SOAR can support faster and safer autonomous mitigation when learning rewards balance threat containment with operational continuity.

Downloads

Published

2021-11-17

Issue

Section

Articles