This paper proposes a methodology for detecting and localizing cyber threats in cloud environments integrated with IoT components. The approach relies on two complementary models: the Cyber-Threat Detection Graph (CTDG), which captures the multi-layered structure of attacks while accounting for risk, latency, and propagation potential; and the Cyberattack Alert Mapping Graph (CAMG), which models temporal–causal dependencies among events to reveal complex and combined threats. CAMG enables the construction of sequential event chains from telemetry, logs, and behavioral anomalies, integrating data from cloud services and IoT devices. This makes it possible not only to identify individual incidents but also to forecast the evolution of multi-stage attacks. To select response options, a generalized evaluation metric is applied that considers the effectiveness of threat localization, service continuity, and the time required to restore system trust. This supports the prioritization of countermeasures while minimizing the impact on critical resources. The proposed methodology blends classical and intelligent threat-analysis techniques, provides proactive monitoring, and remains adaptable
📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً