CLOUD-NATIVE SECURITY INFORMATION AND EVENT MANAGEMENT SYSTEM ON AWS

  • Unique Paper ID: 198895
  • Volume: 12
  • Issue: 11
  • PageNo: 10947-10955
  • Abstract:
  • The rise of cloud-first architectures has transformed enterprise computing but simultaneously expanded the attack surface for security threats. Traditional Security Information and Event Management (SIEM) solutions, while effective for on-premises systems, struggle with scalability, cost, and integration challenges in dynamic cloud environments. This research presents a Cloud-Native SIEM architecture designed and implemented using Amazon Web Services (AWS). The system leverages AWS Lambda, DynamoDB, S3, EventBridge, CloudTrail, and API Gateway to deliver real-time threat detection, alerting, and visualization within a fully serverless ecosystem. The architecture enables centralized log ingestion, normalization, and analysis from synthetic and real-world AWS CloudTrail events. Implemented under AWS Free Tier constraints, the solution demonstrates how serverless paradigms can achieve cost-efficient, scalable, and resilient SIEM operations. Testing indicates ingestion throughput exceeding 1000 events/minute with latency below 200 ms, proving its viability for academic, small business, and low-cost enterprise deployments. Future improvements include integration with Amazon GuardDuty, machine learning-based anomaly detection, and multi-source event correlation.

Copyright & License

Copyright © 2026 Authors retain the copyright of this article. This article is an open access article distributed under the Creative Commons Attribution License which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.

BibTeX

@article{198895,
        author = {Polimati Keerthan and Ankireddy Venkata Uday Karthik and Sonu Singh and Kshitiz Rohilla},
        title = {CLOUD-NATIVE SECURITY INFORMATION AND EVENT MANAGEMENT SYSTEM ON AWS},
        journal = {International Journal of Innovative Research in Technology},
        year = {2026},
        volume = {12},
        number = {11},
        pages = {10947-10955},
        issn = {2349-6002},
        url = {https://ijirt.org/article?manuscript=198895},
        abstract = {The rise of cloud-first architectures has transformed enterprise computing but simultaneously expanded the attack surface for security threats. Traditional Security Information and Event Management (SIEM) solutions, while effective for on-premises systems, struggle with scalability, cost, and integration challenges in dynamic cloud environments. This research presents a Cloud-Native SIEM architecture designed and implemented using Amazon Web Services (AWS). The system leverages AWS Lambda, DynamoDB, S3, EventBridge, CloudTrail, and API Gateway to deliver real-time threat detection, alerting, and visualization within a fully serverless ecosystem. The architecture enables centralized log ingestion, normalization, and analysis from synthetic and real-world AWS CloudTrail events. Implemented under AWS Free Tier constraints, the solution demonstrates how serverless paradigms can achieve cost-efficient, scalable, and resilient SIEM operations. Testing indicates ingestion throughput exceeding 1000 events/minute with latency below 200 ms, proving its viability for academic, small business, and low-cost enterprise deployments. Future improvements include integration with Amazon GuardDuty, machine learning-based anomaly detection, and multi-source event correlation.},
        keywords = {SIEM, Cloud Security, AWS, Serverless, EventBridge},
        month = {April},
        }

Cite This Article

Keerthan, P., & Karthik, A. V. U., & Singh, S., & Rohilla, K. (2026). CLOUD-NATIVE SECURITY INFORMATION AND EVENT MANAGEMENT SYSTEM ON AWS. International Journal of Innovative Research in Technology (IJIRT), 12(11), 10947–10955.

Related Articles