AI-Driven Risk Analysis in DevOps-Based Cloud-Native Payment Systems

Authors

  • Vikram Boga Author
    Competing Interests

    AI,ML

DOI:

https://doi.org/10.5281/zenodo.22173969

Keywords:

DevOps, financial services, payments, security, cloud, microservices, infrastructure, continuous delivery, automation, generative AI.

Abstract

The increasing frequency, sophistication, and financial impact of cyberattacks against financial institutions demand a proactive instead of a reactive approach. One current direction consists of the adoption of Cloud-Native Architecture principles supported by DevOps practices driven by Automation and AIOps tools supplied as-a-Service by cloud providers. Taking into consideration the property of security for the deployment of Payment Systems is paramount, it is proposed a Security-as-a-Service solution using Generative Artificial Intelligence techniques to induce Risk Models. This approach applied within the Design-and-Build phases of the DevOps Automation might link the application code with the risk/security posture of the Payment System and support effective decision-making regarding the acceptance/rejection of the software deployment or update.

Generative Artificial Intelligence techniques have been used for textual completion since the introduction of the Transformer architecture. It can be used to induce Risk Models since usually a Risk Model can be represented in a tabular structure summarized by its three fundamental components: Asset, Threat, and Vulnerability. Recent advances in confidential computing and secure enclaves enable the processing of sensitive information without exposing the input data.

References

1. Aljumah, A. (2020). Cyber security threats, challenges and defence mechanisms in cloud computing. IET Communications, 14(17), 2866–2873.

2. Alouffi, B., Hasnain, M., Alharbi, A., Alosaimi, W., Alyami, H., & Ayaz, M. (2021). A systematic literature review on cloud computing security: Threats and mitigation strategies. IEEE Access, 9, 57792–57807.

3. Akbar, M. A., Smolander, K., Mahmood, S., & Alsanad, A. (2022). Toward successful DevSecOps in software development organizations: A decision-making framework. Information and Software Technology, 147, 106894.

4. Yandamuri, U. S. (2021). A Comparative Study of Traditional Reporting Systems versus Real-Time Analytics Dashboards in Enterprise Operations. Universal Journal of Business and Management, 1(1), 1-13.

5. Al-Hashedi, K. G., & Magalingam, P. (2021). Financial fraud detection applying data mining techniques: A comprehensive review from 2009 to 2019. Computer Science Review, 40, 100402.

6. Chernyshev, M., Baig, Z., & Zeadally, S. (2021). Cloud-native application security: Risks, opportunities, and challenges in securing the evolving attack surface. Computer, 54(11), 47–57.

7. Faustino, J. (2022). DevOps benefits: A systematic literature review. Software: Practice and Experience, 52(9), 1905–1926.

8. Hilal, W., Gadsden, S. A., & Yawney, J. (2022). Financial fraud: A review of anomaly detection techniques and recent advances. Expert Systems with Applications, 193, 116429.

9. Jarkas, O., Ko, R., Dong, N., & Mahmud, R. (2021). A review of security risks and countermeasures in containers. International Journal of Security and Networks, 16(3), 183–190.

10. Kumar, R., & Goyal, R. (2020). Modeling continuous security: A conceptual model for automated DevSecOps using open-source software over cloud (ADOC). Computers & Security, 97, 101967.

11. Martínez-Magdaleno, S., Morales-Rocha, V., & Parra, R. (2021). A review of security risks and countermeasures in containers. International Journal of Security and Networks, 16(3), 183–190.

12. Rajapakse, R. N., Zahedi, M., Babar, M. A., & Shen, H. (2022). Challenges and solutions when adopting DevSecOps: A systematic review. Information and Software Technology, 141, 106700.

13. Ti, Y.-W., Hsin, Y.-Y., Dai, T.-S., Huang, M.-C., & Liu, L.-C. (2022). Feature generation and contribution comparison for electronic fraud detection. Scientific Reports, 12, 18042.

14. Waseem, M., Liang, P., & Shahin, M. (2020). A systematic mapping study on microservices architecture in DevOps. Journal of Systems and Software, 170, 110798.

15. Wong, A. Y., Chekole, E. G., Ochoa, M., & Zhou, J. (2021). Threat modeling and security analysis of containers: A survey. Proceedings of the 2021 IEEE International Conference on Cyber Security and Resilience.

16. Kumar, U., & Sreeramulu, D. (2022). Ensuring compliance and security in cloud-native digital payment platforms. International Journal of Computer Engineering and Technology, 13(3), 211–227.

17. Muthusamy, M. (2022). AI-enhanced DevSecOps architecture for cloud-native banking secure distributed systems with deep neural networks and automated risk analytics. International Journal of Research Publications in Engineering, Technology and Management, 5(6).

18. Bouchard Clark, L. F. (2022). A cloud-native AI architecture for financial network protection: Multivariate threat pattern analytics with DevSecOps and big data-driven ERP security. International Journal of Advanced Research in Computer Science & Technology, 5(2).

19. Muthuraman, S., Das, D., & Mohammed, A. S. (2022). Advanced threat detection and mitigation strategies for financial cloud systems using AI and ML. Journal of Artificial Intelligence Research and Applications.

20. Kumar, P. V. Y. (2022). A secure cloud-native API architecture for banking: Integrating zero-trust controls and data-science-driven threat intelligence. International Journal of Communication Networks and Information Security, 14(3), 1368–1393.

21. Ekström, J. K. B. (2022). A cloud security hyper-automation model for financial markets and ERP healthcare AI-driven anomaly detection, multivariate risk inference, and continuous DevSecOps assurance. International Journal of Research Publications in Engineering, Technology and Management, 5(5).

22. Anjaria, D., & Kulkarni, M. (2022). Effective DevSecOps implementation: A systematic literature review. Cardiometry, 24, 410–417.

23. Kathiresan, G. (2022). Evaluating the impact of DevSecOps on software quality: A systematic review and empirical study. World Journal of Advanced Research and Reviews, 14(1), 644–653.

24. Mangalampalli, B. M. (2021). Scalable Data Warehouse Architecture for Population Health Management and Predictive Analytics. World Journal of Clinical Medicine Research, 1(1), 1-18.

25. Farsi, M., Ali, M., Shah, R. A., Wagan, A. A., Kharabsheh, R., & Farouk, A. (2020). Cloud computing and data security threats taxonomy: A review. Journal of Information Security and Applications, 52, 102642.

26. Zissis, D., & Lekkas, D. (2020). Addressing cloud computing security issues. Future Generation Computer Systems, 107, 620–644.

27. Choudhary, S., & Goyal, R. (2020). Moving target defense in cloud computing: A systematic mapping study. Computers & Security, 92, 101742.

Additional Files

Published

2023-12-20

Data Availability Statement

None

How to Cite

AI-Driven Risk Analysis in DevOps-Based Cloud-Native Payment Systems. (2023). The American Journal of Analytics and Artificial Intelligence (AJAAI), 1(01). https://doi.org/10.5281/zenodo.22173969

Most read articles by the same author(s)

Similar Articles

31-36 of 36

You may also start an advanced similarity search for this article.