Title: A comparative performance analysis of automated cloud security remediation architectures for AWS cloud environments
Authors: Vitalii Molnar; Dmytro Sabodashko; Ivan Opirskyy
Addresses: Department of Information Security, Lviv Polytechnic National University, 12 Stepana Bandery St., Lviv, 79013, Ukraine ' Department of Information Security, Lviv Polytechnic National University, 12 Stepana Bandery St., Lviv, 79013, Ukraine ' Department of Information Security, Lviv Polytechnic National University, 12 Stepana Bandery St., Lviv, 79013, Ukraine
Abstract: This research evaluates the performance of three remediation strategies for addressing critical cloud-security misconfigurations: manual intervention, polling-based automation, and event-driven automation. Experiments were conducted within a single AWS account and region under controlled load, simulating two high-impact yet relatively simple scenarios: public-data exposure through storage-policy modification and unrestricted remote access due to security-group misconfiguration. Each approach was assessed using key metrics - time to detect (TTD), time to remediate (TTR), and total automated response time (T_ART) - across repeated trials to ensure statistical validity, assuming remediation functions remained in a warm state. Within this constrained experimental setting, event-driven remediation achieved the lowest response times, consistently below ten seconds, whereas polling-based and manual methods exhibited substantially higher latency. These findings suggest that, for similar classes of misconfigurations and deployment conditions, event-driven workflows can provide faster and more consistent remediation, potentially reducing the dwell time of misconfigurations, although generalisation to multi-region and large-scale environments requires further investigation.
Keywords: cloud security; cloud misconfiguration; automated remediation; event-driven architecture; AWS Config; Amazon EventBridge; response latency; security automation; performance benchmarking.
DOI: 10.1504/IJICS.2026.154858
International Journal of Information and Computer Security, 2026 Vol.30 No.3, pp.373 - 393
Received: 01 Sep 2025
Accepted: 20 Dec 2025
Published online: 16 Jul 2026 *