Adaptive threat intelligence models for protecting educational cloud infrastructures
Abstract
The quick transfer of academic processes to cloud-based systems has increased the cyber-attack area of academic institutions significantly by introducing systemic weaknesses into the learning management systems (LMS), enterprise resource planning (ERP) tools, as well as databases housing student data. Traditional security controls, relying mostly on fixed signature databases and rule-based intrusion detection, are no longer effective against polymorphic malware, zero-day attacks, and advanced insider threats that define contemporary adversarial environments. Nevertheless, even with the emergence of cloud-native security tools, educational organisations are experiencing a high level of false positives, slower response to threats, and an almost complete inability to predict new vectors of attacks. Lacking contextually sensitive self-updating intelligence pipes exposes campus networks to cascading failures that threaten the privacy of students, integrity of research data, and compliance with regulations. This paper introduces Adaptive Threat Intelligence Learning Algorithm (ATILA), a five-layer security architecture, which combines transformer-based anomaly detection, reinforcement-learning-based policy coordination and federated collaborative defence in geographically distributed institutional nodes. Three benchmark datasets were used to evaluate ATILA: UNSW-NB15, CICIDS-2018 and a simulated corpus of campus cloud logs simulating a federated multi-campus environment. They were compared to rule-based, intrusion detection systems, and non-adaptive deep learning models and rule-based classifiers based on the static random forest. ATILA had 98.3% and 1.4% detection and false positive rates, respectively, which is 4.6 and 8.3 % points better than the most successful non-adaptive baseline. The recall of the zero-day detection went to 91.7 and the mean time of the threat response came down to 6.1 ms. University LMS environments, multi-campus cloud federations, and online examination systems all receive deployment ready design specifications that provide a repeatable pathway towards institutions wishing to operationalise adaptive AI-driven security at scale.