NORMA eResearch @NCI Library

Unified Multi-Feed Anomaly Detection for AWS Lambda

Ethape, Devshree Chandrakant Chandrakant (2025) Unified Multi-Feed Anomaly Detection for AWS Lambda. Masters thesis, Dublin, National College of Ireland.

[thumbnail of Master of Science]
Preview
PDF (Master of Science)
Download (734kB) | Preview
[thumbnail of Configuration Manual]
Preview
PDF (Configuration Manual)
Download (3MB) | Preview

Abstract

Serverless computing has been increasing at a rapid pace, but AWS Lambda does not offer coherent telemetry, host-levels, and powerful real-time anomaly detection. Such restrictions do not allow for promptly detecting performance degradation, cost-based attacks, and cold-start-related disturbances and render serverless observability an urgent research issue. To resolve this issue, the paper formulates and tests a completely AWS-native, real-time anomaly detector pipeline, which combines multi-source telemetry gatherings on CloudWatch, EventBridge and Lambda into a solitary Kinesis-Flink analytics bear.

The work is constructed in Design Science Research Methodology by creating an operational artefact which consists of ingestion through Kinesis Data Streams, in-stream analysis through Apache Flink SQL and automated anomaly alerts through Amazon SNS. Implementation of a threshold-based detection logic was conducted to detect an anomaly in terms of execution-time, and controlled experiments with synthetic attack patterns tested how well the model can detect an abnormal behaviour with accuracy and virtually in-time responsiveness.

The results present a theoretical argument that serverless observability is possible without host-level indicators based on integrated streams of telemetry hosted at the cloud, which correlates with the current body of work on Lambda-based security architecture. Practically the pipeline offers a very scalable and non-overhead mechanism of anomaly detection that can function in conjunction with current cloud operations. Nevertheless, there are still unresolved issues, such as the use of single-metric thresholds, the lack of machine-learning intelligence, and restricted multi-signal correlation, which bring opportunities to practice Isolation Forest or auto encoders-based detector models in the future.

Item Type: Thesis (Masters)
Supervisors:
Name
Email
Mijumbi, Rashid
UNSPECIFIED
Subjects: T Technology > T Technology (General) > Information Technology > Cloud computing
Q Science > Q Science (General) > Self-organizing systems. Conscious automata > Machine learning
Divisions: School of Computing > Master of Science in Cloud Computing
Depositing User: Ciara O'Brien
Date Deposited: 31 Aug 2026 14:07
Last Modified: 31 Aug 2026 14:07
URI: https://norma.ncirl.ie/id/eprint/9699

Actions (login required)

View Item View Item