Intelligent Attack Detection in Blockchain-Enabled Multi-Cloud Systems: A Systematic Review and SOC-LLM-Augmented Architecture Proposal
Abstract
1. Introduction
2. Background
2.1. Integration of Blockchain in a Multi-Cloud System
2.2. Blockchain and IAM
2.3. SOC-LLM and Agentic Threat Detection
2.4. LLMs in Cybersecurity: Recent Advances and Relevance to SOC Operations
2.4.1. AI-Assisted SOC Operations and Security Copilots
2.4.2. Agent-Based Security Architectures and Retrieval-Augmented Security Analysis
3. Related Works
4. Research Methodology
4.1. Research Question
- (1)
- What advantages may the integration of blockchain technology provide to a multi-cloud system?
- (2)
- How can the six newly discovered security dimensions be addressed with blockchain technology?
- (3)
- Can blockchain technology be integrated with other technologies to address the six security threat vectors in multi-cloud environments?
- (4)
- How can the blockchain-based multi-cloud system be effectively safeguarded against the six security dimensions outlined in this article?
- (5)
- What advantages can we gain from modern technology to successfully address these challenges?
4.2. Identification of Research
4.2.1. Sources of Research
4.2.2. Criteria Selection
4.2.3. Research Strategy
4.2.4. Selection Process and Exclusion Criteria for Relevant Studies
- -
- Identification: 1283 articles were initially identified through database searches.
- -
- Screening: After removing 296 duplicate articles, the titles and abstracts of the remaining 987 articles were screened.
- -
- Eligibility: 66 articles were selected for full-text review.
- -
- Inclusion: 24 studies met all criteria and were included in the final analysis.
4.2.5. Study Selection and Quality Assessment
5. Results and Discussion
5.1. Taxonomy of Blockchain-Based Multi-Cloud Security
5.1.1. Architecture
5.1.2. API
5.1.3. Authentication
5.1.4. Multi-Cloud Automation and Orchestration
5.1.5. SLA Management (Security Accountability Domain)
5.1.6. Cybersecurity Compliance (Governance and Auditability Domain)
5.2. Blockchain-Based Security Solutions and Comparative Analysis of Reviewed Studies
6. Proposed SOC-LLM-Augmented Architecture
6.1. Security Data Layer
6.2. Statistical and Machine-Learning Detection Layer
6.3. SOC-LLM Agentic Layer
6.4. Blockchain Trust Layer
6.5. SOC Dashboard and Response
6.6. Agent Collaboration Workflow and Prompt-Constrained Reasoning
6.7. Prompt Templates and Contextual Constraints
You are the Oversight Agent for a Security Operations Center. Mission: Validate attack assessments produced by subordinate agents. Constraints: • Use only the supplied evidence. • Do not introduce external facts. • Reject conclusions not supported by evidence. • Output must follow the specified JSON schema. Input: { “incident_id”: “INC-245”, “attack_type”: “Authentication Abuse”, “confidence”: 0.91, “severity”: “HIGH”, “evidence_ids”: [“TX1045”,”LOG782”,”AUTH558”] } Output: { “validated”: true, “risk_score”: 92, “recommended_action”: “Temporarily block the account and initiate identity verification.” }
You are an Explanation Agent supporting SOC analysts. Mission: Transform technical detections into human-readable incident reports. Constraints: • Explain only verified evidence. • Do not generate new facts. • Maintain traceability to evidence identifiers. Input: { “attack_type”: “Credential Abuse”, “severity”: “HIGH”, “confidence”: 0.94, “evidence”: [“AUTH558”,”TX1045”,”LOG782”] } Output: |
6.8. Preliminary Validation Strategy and Simulation Protocol
7. Limits and Future Directions
- -
- Blockchain-enabled multi-cloud systems lack standardized security mechanisms.
- -
- Scalability constraints of blockchain consensus mechanisms.
- -
- Limited interoperability among cloud service providers.
- -
- Inadequate criteria for evaluating cloud security solutions based on blockchain technology.
8. Conclusions
Author Contributions
Funding
Data Availability Statement
Conflicts of Interest
References
- Columbus, C. Ensuring Secure and Efficient Multi-Cloud Storage with Brotli Compression and Hierarchical Data Protection. Res. Sq. 2023. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Khanna, A.; Sah, A.; Bolshev, V.; Burgio, A.; Panchenko, V.; Jasiński, M. Blockchain–Cloud Integration: A Survey. Sensors 2022, 22, 5238. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Kumar, M.; Maple, C.; Chand, S. An Efficient and Secure Identity-Based Integrity Auditing Scheme for Sensitive Data with Anti-Replacement Attack on Multi-Cloud Storage. J. King Saud Univ.-Comput. Inf. Sci. 2023, 35, 101745. [Google Scholar] [CrossRef] [Scilit]
- Miyachi, K.; Mackey, T.K. hOCBS: A Privacy-Preserving Blockchain Framework for Healthcare Data Leveraging an on-Chain and off-Chain System Design. Inf. Process. Manag. 2021, 58, 102535. [Google Scholar] [CrossRef] [Scilit]
- Yu, H.; Hu, Q.; Yang, Z.; Liu, H. Efficient Continuous Big Data Integrity Checking for Decentralized Storage. IEEE Trans. Netw. Sci. Eng. 2021, 8, 1658–1673. [Google Scholar] [CrossRef] [Scilit]
- Rosini, A.; Mestriner, D.; Labella, A.; Bonfiglio, A.; Procopio, R. A Decentralized Approach for Frequency and Voltage Regulation in Islanded PV-Storage Microgrids. Electr. Power Syst. Res. 2021, 193, 106974. [Google Scholar] [CrossRef] [Scilit]
- Mishra, R.; Ramesh, D.; Edla, D.R.; Qi, L. DS-Chain: A Secure and Auditable Multi-Cloud Assisted EHR Storage Model on Efficient Deletable Blockchain. J. Ind. Inf. Integr. 2022, 26, 100315. [Google Scholar] [CrossRef] [Scilit]
- Li, D.; Du, R.; Au, M.H.; Fu, Y. Meta-Key: A Secure Data-Sharing Protocol under Blockchain-Based Decentralised Storage Architecture. IEEE Netw. Lett. 2019, 1, 30–33. [Google Scholar] [CrossRef] [Scilit]
- Demertzis, K.; Rantos, K.; Magafas, L.; Skianis, C.; Iliadis, L. A Secure and Privacy-Preserving Blockchain-Based XAI-Justice System. Information 2023, 14, 477. [Google Scholar] [CrossRef] [Scilit]
- Enge, A.; Satybaldy, A.; Nowostawski, M. An Offline Mobile Access Control System Based on Self-Sovereign Identity Standards. Comput. Netw. 2022, 219, 109434. [Google Scholar] [CrossRef] [Scilit]
- Sutradhar, S.; Karforma, S.; Bose, R.; Roy, S.; Djebali, S.; Bhattacharyya, D. Enhancing Identity and Access Management Using Hyperledger Fabric and OAuth 2.0: A Block-Chain-Based Approach for Security and Scalability for Healthcare Industry. Internet Things Cyber-Phys. Syst. 2024, 4, 49–67. [Google Scholar] [CrossRef] [Scilit]
- Taylor, P.J.; Dargahi, T.; Dehghantanha, A.; Parizi, R.M.; Choo, K.-K.R. A Systematic Literature Review of Blockchain Cyber Security. Digit. Commun. Netw. 2020, 6, 147–156. [Google Scholar] [CrossRef] [Scilit]
- Sudarsan, S.V.; Schelen, O.; Bodin, U. Survey on Delegated and Self-Contained Authorization Techniques in CPS and IoT. IEEE Access 2021, 9, 98169–98184. [Google Scholar] [CrossRef] [Scilit]
- Sim, W.L.; Chua, H.N.; Tahir, M. Blockchain for Identity Management: The Implications to Personal Data Protection. In Proceedings of the 2019 IEEE Conference on Application, Information and Network Security (AINS), Pulau Pinang, Malaysia, 19–21 November 2019; IEEE: Piscataway, NJ, USA, 2019; pp. 30–35. [Google Scholar]
- Ferrag, M.A.; Ndhlovu, M.; Tihanyi, N.; Cordeiro, L.C.; Debbah, M.; Lestable, T.; Thandi, N.S. Revolutionizing Cyber Threat Detection with Large Language Models: A Privacy-Preserving BERT-Based Lightweight Model for IoT/IIoT Devices. IEEE Access 2023, 12, 40. [Google Scholar] [CrossRef] [Scilit]
- Deng, G.; Liu, Y.; Mayoral-Vilches, V.; Liu, P.; Li, Y.; Xu, Y.; Zhang, T.; Liu, Y.; Pinzger, M.; Rass, S. PentestGPT: An LLM-Empowered Automatic Penetration Testing Tool. arXiv 2023, arXiv:2308.06782. [Google Scholar]
- Xu, J.; Stokes, J.W.; McDonald, G.; Bai, X.; Marshall, D.; Wang, S.; Swaminathan, A.; Li, Z. AutoAttacker: A Large Language Model Guided System to Implement Automatic Cyber-Attacks. arXiv 2024, arXiv:2403.01038. [Google Scholar]
- Zeng, C.; He, D.; Feng, Q.; Yang, X.; Luo, Q. SecureGPT: A Framework for Multi-Party Privacy-Preserving Transformer Inference in GPT. IEEE Trans. Inform. Forensic Secur. 2024, 19, 9480–9493. [Google Scholar] [CrossRef] [Scilit]
- Reece, M.; Lander, T.E., Jr.; Stoffolano, M.; Sampson, A.; Dykstra, J.; Mittal, S.; Rastogi, N. Systemic Risk and Vulnerability Analysis of Multi-Cloud Environments. arXiv 2023, arXiv:2306.01862. [Google Scholar]
- Checkpoint Software. Cloud Security Report: Check Point Software; Checkpoint Software: Tel Aviv, Israel, 2022. [Google Scholar]
- Zhang, Y.; Geng, H.; Su, L.; Lu, L. A Blockchain-Based Efficient Data Integrity Verification Scheme in Multi-Cloud Storage. IEEE Access 2022, 10, 105920–105929. [Google Scholar] [CrossRef] [Scilit]
- Zahed Benisi, N.; Aminian, M.; Javadi, B. Blockchain-Based Decentralized Storage Networks: A Survey. J. Netw. Comput. Appl. 2020, 162, 102656. [Google Scholar] [CrossRef] [Scilit]
- Sabeena, S.J.; Vijila, S.A. Blockchain-Based Solution for Securing Job Card Data Integrity and Payment System Using Bi-Quad Merkle Tree. Int. J. Intell. Syst. Appl. Eng. 2024, 12, 314–328. [Google Scholar]
- Gujar, V. Identity management, SSI and blockchain: A review. Int. J. Sci. Res. 2023, 8, 38–45. [Google Scholar] [CrossRef] [Scilit]
- Alamri, B.; Crowley, K.; Richardson, I. Blockchain-Based Identity Management Systems in Health IoT: A Systematic Review. IEEE Access 2022, 10, 59612–59629. [Google Scholar] [CrossRef] [Scilit]
- Vakilinia, I.; Wang, W.; Xin, J. An Incentive-Compatible Mechanism for Decentralized Storage Network. IEEE Trans. Netw. Sci. Eng. 2023, 10, 2294–2306. [Google Scholar] [CrossRef] [Scilit]
- Aldriwish, K. A Double-Blockchain Architecture for Secure Storage and Transaction on the Internet of Things Networks. Int. J. Comput. Sci. Netw. Secur. 2021, 21, 119–126. [Google Scholar] [CrossRef]
- Kitchenham, B. Procedures for Performing Systematic Reviews; Keele University: Keele, UK, 2004. [Google Scholar]
- Gangadhara, B. Exploiting AI and source blockchain framework to mitigate risks in cloud manufacturing in industry 3.0. Int. J. Multidiscip. Eng. Curr. Res. 2021, 6, 11–26. [Google Scholar]
- Zahir, A.; Groshev, M.; Antevski, K.; J.Bernardos, C.; Ayimba, C.; De La Oliva, A. Performance Evaluation of Private and Public Blockchains for Multi-Cloud Service Federation. In Proceedings of the 25th International Conference on Distributed Computing and Networking, Chennai, India, 4 January 2024; ACM: New York, NY, USA, 2024; pp. 217–221. [Google Scholar]
- SH, A.S.; TS, L.P.; Sunitha, T.; Sriman, B.; NK, S.K.; Subin, S.S. A Secure and Efficient Blockchain-Based Multi-Cloud Medical File Sharing. In Proceedings of the 2023 International Conference on Advances in Computing, Communication and Applied Informatics (ACCAI); IEEE: Piscataway, NJ, USA, 2023; pp. 1–7. [Google Scholar]
- Irshad, R.R.; Hussain, S.; Hussain, I.; Nasir, J.A.; Zeb, A.; Alalayah, K.M.; Alattab, A.A.; Yousif, A.; Alwayle, I.M. IoT-Enabled Secure and Scalable Cloud Architecture for Multi-User Systems: A Hybrid Post-Quantum Cryptographic and Blockchain Based Approach Towards a Trustworthy Cloud Computing. IEEE Access 2023, 11, 105479–105498. [Google Scholar] [CrossRef] [Scilit]
- Sravanthi, K.; Sekhar, P.C. An Efficient Integrity Verification Based Multi-User Cloud Access Control Framework Using Block Chain Technology on EHR Database. Int. J. Intell. Syst. Appl. Eng. 2024, 12, 536–549. [Google Scholar] [CrossRef] [Scilit]
- Zhou, M.; Xiao, P.; Wang, Q.; Ruan, S.; Chen, X.; Yang, M. Enhancing the Trustworthiness of 6G Based on Trusted Multi-Cloud Infrastructure: A Practice of Cryptography Approach. CMES-Comput. Model. Eng. Sci. 2024, 138, 957. [Google Scholar] [CrossRef] [Scilit]
- Ragu, G.; Ramamoorthy, S. A Blockchain-Based Cloud Forensics Architecture for Privacy Leakage Prediction with Cloud. Healthc. Anal. 2023, 4, 100220. [Google Scholar] [CrossRef] [Scilit]
- Arias Maestro, A.; Sanjuán Martínez, Ó.; Teredesai, A.M.; García-Díaz, V. Blockchain Based Cloud Management Architecture for Maximum Availability. Int. J. Interact. Multimed. Artif. Intell. 2023, 8, 88–94. [Google Scholar] [CrossRef] [Scilit]
- Zeydan, E.; Baranda, J.; Mangues-Bafalluy, J. Post-Quantum Blockchain-Based Secure Service Orchestration in Multi-Cloud Networks. IEEE Access 2022, 10, 129520–129530. [Google Scholar] [CrossRef] [Scilit]
- Wu, Q.; Lai, T.; Zhang, L.; Mu, Y.; Rezaeibagha, F. Blockchain-Enabled Multi-Authorization and Multi-Cloud Attribute-Based Keyword Search over Encrypted Data in the Cloud. J. Syst. Archit. 2022, 129, 102569. [Google Scholar] [CrossRef] [Scilit]
- Ramadhan, A.N.; Pane, K.N.; Wardhana, K.R. Blockchain and API Development to Improve Relational Database Integrity and System Interoperability. Procedia Comput. Sci. 2023, 216, 151–160. [Google Scholar] [CrossRef] [Scilit]
- Pasdar, A.; Lee, Y.C.; Dong, Z. Connect API with Blockchain: A Survey on Blockchain Oracle Implementation. ACM Comput. Surv. 2023, 55, 1–39. [Google Scholar] [CrossRef] [Scilit]
- Baucas, M.J.; Spachos, P. Permissioned Blockchain Reinforced API Platform for Data Management in IoT-Based Sensor Networks. In Proceedings of the 2021 IEEE Global Communications Conference (GLOBECOM); IEEE: Piscataway, NJ, USA, 2021; pp. 1–6. [Google Scholar]
- Scheid, E.J.; Kiechl, P.; Franco, M.; Rodrigues, B.; Killer, C.; Stiller, B. Security and Standardization of a Notary-Based Blockchain Interoperability API. In Proceedings of the 2021 Third International Conference on Blockchain Computing and Applications (BCCA); IEEE: Piscataway, NJ, USA, 2021; pp. 42–48. [Google Scholar]
- Sivagami, V.M.; EaswaraKumar, K.S.; Jayanthi, D.; Kalavathi, S. Blockchain-Integrated Decentralized Fault Tolerance for Secure and Energy-Efficient Multi-Cloud Interoperability. Sustain. Comput. Inform. Syst. 2025, 47, 101170. [Google Scholar] [CrossRef] [Scilit]
- Zeydan, E.; Baranda, J.; Mangues-Bafalluy, J.; Arslan, S.S.; Turk, Y. A Trustworthy Framework for Multi-Cloud Service Management: Self-Sovereign Identity Integration. IEEE Trans. Netw. Sci. Eng. 2024, 11, 3135–3147. [Google Scholar] [CrossRef] [Scilit]
- Awadallah, R.; Samsudin, A.; Teh, J.S.; Almazrooie, M. An Integrated Architecture for Maintaining Security in Cloud Computing Based on Blockchain. IEEE Access 2021, 9, 69513–69526. [Google Scholar] [CrossRef] [Scilit]
- Son, S.; Lee, J.; Kim, M.; Yu, S.; Das, A.K.; Park, Y. Design of Secure Authentication Protocol for Cloud-Assisted Telecare Medical Information System Using Blockchain. IEEE Access 2020, 8, 192177–192191. [Google Scholar] [CrossRef] [Scilit]
- Rompicharla, R. Continuous Compliance Model for Hybrid Multi-Cloud through Self-Service Orchestrator. In Proceedings of the 2020 International Conference on Smart Technologies in Computing, Electrical and Electronics (ICSTCEE); IEEE: Piscataway, NJ, USA, 2020; pp. 589–593. [Google Scholar]
- Verma, R.; Dhanda, N.; Nagar, V. Towards a Secured IoT Communication: A Blockchain Implementation Through APIs. In Proceedings of Third International Conference on Computing, Communications, and Cyber-Security; Singh, P.K., Wierzchoń, S.T., Tanwar, S., Rodrigues, J.J.P.C., Ganzha, M., Eds.; Lecture Notes in Networks and Systems; Springer Nature: Singapore, 2023; Volume 421, pp. 681–692. [Google Scholar]
- Sun, J.; Wu, C.; Ye, J. Blockchain-Based Automated Container Cloud Security Enhancement System. In Proceedings of the 2020 IEEE International Conference on Smart Cloud (SmartCloud); IEEE: Piscataway, NJ, USA, 2020; pp. 1–6. [Google Scholar]
- Hoang, H.D.; Duy, P.T.; Pham, V.-H. A Security-Enhanced Monitoring System for Northbound Interface in SDN Using Blockchain. In Proceedings of the Tenth International Symposium on Information and Communication Technology—SoICT 2019, Hanoi, Ha Long Bay, Vietnam, 4–6 December 2019; ACM Press: New York, NY, USA, 2019; pp. 197–204. [Google Scholar]
- Patil, B. Integration of Blockchain with AWS and Azure for Enhanced Cloud Security and Compliance in Multi-Cloud Architectures. In Proceedings of the 2025 International Conference on Computing and Communication Technologies (ICCCT), Chennai, India, 16 April 2025; IEEE: Piscataway, NJ, USA, 2025; pp. 1–5. [Google Scholar]
- Abhishek, P.M.; Chobari, A.; Narayan, D.G. SLA Violation Detection in Multi-Cloud Environment Using Hyperledger Fabric Blockchain. In Proceedings of the 2021 IEEE International Conference on Distributed Computing, VLSI, Electrical Circuits and Robotics (DISCOVER), Nitte, India, 19 November 2021; IEEE: Piscataway, NJ, USA, 2021; pp. 107–112. [Google Scholar]
- Khraisat, A.; Gondal, I.; Vamplew, P.; Kamruzzaman, J. Survey of Intrusion Detection Systems: Techniques, Datasets and Challenges. Cybersecurity 2019, 2, 20. [Google Scholar] [CrossRef] [Scilit]





| Paper Type | Title | Major Contribution | Features Research Directions | Year | Reference |
|---|---|---|---|---|---|
| Research | Bi-Quad Merkle Tree-Based Blockchain-Based Approach to Protect Job Card Data Integrity and Payment System | Suggested a methodology to protect data using the RSA and DES (MRDES) encryption algorithm while lowering the compute cost and temporal complexity of the transactions management process. | Add lightweight cryptography based on block contents to the model to further improve resilience against security risks and further minimize complexity. | 2024 | [23] |
| Review | Identity Management, SSI and Blockchain: A Review | integration and combination of blockchain technology and Facial Recognition Technology (FRT) in Self-sovereign identity (SSI) to ensure identity performance and security. | Using SSI to drive a biometric revolution that goes beyond conventional identity management, providing a simple and safe authentication procedure across a range of industries. Accessing government services, medical records, or financial transactions is made faster and more secure when Facial Recognition Technology is connected with SSI. | 2023 | [24] |
| Research | Using Hierarchical Data Protection with Brotli Compression to Provide Safe and Effective Multi-Cloud Storage. | A system that utilizes the MD5 algorithm and the Brotli compression method is suggested to guarantee data integrity, minimize data size, and facilitate speedier transmission. | For cold files that don’t require frequent read–write operations, the suggested approach works better. This, if the files needed read–write operations, is the performance accuracy. | 2023 | [1] |
| Survey | Blockchain-Based Identity Management Systems in Health Iot: A Systematic Review. | A systematic literature review on the blockchain-based IAM in Health IOT. They compared 24 studies in terms of IAM based on blockchain in Health IOT. | The creation of an all-encompassing security framework for Internet of Things applications using BC-based IAM systems. | 2022 | [25] |
| Research | Decentralized Storage Network | It has suggested a method for effectively regulating the storage agreement between the customer and storage provider by utilizing the Oracle network and smart contracts. | The legitimacy of the outcome can be increased by using the Oracle network and smart contract to control the storage contract regulations. | 2022 | [26] |
| Review | Blockchain-Based Secure Storage | To increase the security of communication transactions, an information compression technique based on double blockchains was presented for stored data. | When using the RSA and DSA algorithms, the accuracy of the suggested system can reach 96%. | 2021 | [27] |
| Exclusion Criteria | Inclusion Criteria |
|---|---|
|
|
| Database | Website |
|---|---|
| ACM | https://www.acm.org/ (accessed on 15 May 2024) |
| IEEE | https://ieeexplore.ieee.org/ (accessed on 15 May 2024) |
| IJIMAI | https://www.ijimai.org/journal/ (accessed on 15 May 2024) |
| Science Direct | https://www.sciencedirect.com/ (accessed on 15 May 2024) |
| Scopus | https://www.scopus.com/pages/home (accessed on 15 May 2024) |
| Web of Science | https://webofscience.com/ (accessed on 15 May 2024) |
| Criteria | The Equivalent |
|---|---|
| Population Action Evaluation Results |
|
| The Factor for Evaluating the Quality | Yes | No |
|---|---|---|
| Is the research question addressed in the study? | 1 | 0 |
| Is the cloud system implemented using a blockchain platform? | 1 | 0 |
| Is the security of the system considered? | 1 | 0 |
| Study | Title | Authors Names | Type | Year | Publisher | References |
|---|---|---|---|---|---|---|
| S1 | Blockchain-based Solution for Securing Job Card Data Integrity and Payment System using Bi-Quad Merkle Tree | Sabeena and Vijila | Journal Article IJISAE | 2024 | Elsevier | [23] |
| S2 | EXPLOITING AI AND SOURCE BLOCKCHAIN FRAMEWORK TO MITIGATE RISKS IN CLOUD MANUFACTURING IN INDUSTRY3.0 | Gangadhara | Journal Article ijmec | 2021 | ResearchGate | [29] |
| S3 | Performance evaluation of Private and Public Blockchains for multi-cloud service federation | Zahir and al. | Conference paper | 2024 | ACM | [30] |
| S4 | A Secure and Efficient Blockchain-based Multi-Cloud Medical File Sharing | SH and al. | Conference paper | 2023 | IEEE | [31] |
| S5 | IoT-Enabled Secure and Scalable Cloud Architecture for Multi-User Systems: A Hybrid Post-Quantum Cryptographic and Blockchain-based Approach Towards a Trustworthy Cloud Computing | Irshad and al. | Journal Article | 2023 | IEEE | [32] |
| S6 | An Efficient Integrity Verification based Multi-User Cloud Access Control Framework using Block Chain Technology on EHR Database | Sravanthi and Sekhar | Journal Article IJISAE | 2024 | Elsevier | [33] |
| S7 | Enhancing the Trustworthiness of 6G Based on Trusted Multi-Cloud Infrastructure: A Practice of Cryptography Approach. | Zhou and al. | Journal Article | 2024 | CMES | [34] |
| S8 | A blockchain-based cloud forensics architecture for privacy leakage prediction with cloud | Ragu and Ramamoorthy | Journal Article | 2023 | Science Direct | [35] |
| S9 | Blockchain-Based Cloud Management Architecture for Maximum Availability | Arias Maestro and al. | Journal Article | 2023 | IJIMAI | [36] |
| S10 | Post-Quantum Blockchain-Based Secure Service Orchestration in Multi-Cloud Networks | Zeydan and al. | Journal Article | 2022 | IEEE | [37] |
| S11 | Blockchain-enabled multi-authorization and multi-cloud attribute-based keyword search over encrypted data in the cloud | Wu and al. | Journal Article | 2022 | Science Direct | [38] |
| S12 | Blockchain and API Development to Improve Relational Database Integrity and System Interoperability | Ramadhan and al. | Journal Article | 2023 | Science Direct | [39] |
| S13 | Connect API with Blockchain: A Survey on Blockchain Oracle Implementation | Pasdar and al. | Journal Article | 2023 | ACM | [40] |
| S14 | Permissioned Blockchain Reinforced API Platform for Data Management in IoT-based Sensor Networks | Baucas and Spachos | Conference Paper | 2021 | IEEE | [41] |
| S15 | Security and standardization of a notary-based blockchain interoperability API | Scheid and al. | Conference Paper | 2021 | IEEE | [42] |
| S16 | Blockchain-integrated decentralized fault tolerance for secure and energy-efficient multi-cloud interoperability | Sivagami, V.M. and al. | Journal Article | 2025 | Elseiver | [43] |
| S17 | A Trustworthy Framework for Multi-Cloud Service Management: Self-Sovereign Identity Integration | Zeydan and al. | Journal Article | 2024 | IEEE | [44] |
| S18 | An integrated architecture for maintaining security in cloud computing based on blockchain | Awadallah and al. | Journal Article | 2021 | IEEE | [45] |
| S19 | Design of secure authentication protocol for cloud-assisted telecare medical information system using blockchain | Son and al. | Journal Article | 2020 | IEEE | [46] |
| S20 | Continuous Compliance Model for Hybrid Multi-Cloud through Self-Service Orchestrator | Rompicharla | Conference Paper | 2020 | IEEE | [47] |
| S21 | Towards a Secured IoT Communication: A Blockchain Implementation Through APIs | Verma and al. | Book Section | 2023 | Springer | [48] |
| S22 | Blockchain-based automated container cloud security enhancement system | Sun and al. | Conference Paper | 2020 | IEEE | [49] |
| S23 | A Security-Enhanced Monitoring System for Northbound Interface in SDN using Blockchain | Hoang and al. | Conference Paper | 2019 | ACM | [50] |
| S24 | Integration of Blockchain with AWS and Azure for Enhanced Cloud Security and Compliance in Multi-Cloud Architectures | Patil, Balkrishna | Conference Paper | 2025 | IEEE | [51] |
| Study | Application | BC Platform | BC Type | Security Assets | Access Policy |
|---|---|---|---|---|---|
| S1 | Job Cards Payments | Ethereum | Bi-Quad Merkle | integrity, privacy, confidentiality | permissioned |
| S2 | Cloud manufacturing applications | Hyperledger Fabric | private | Data security, predictive auditing, risk management | Permissioned |
| S3 | NFV MANO System | Ethereum | public, private | data integrity, transparency | Permissioned |
| S4 | Healthcare | Hyperledger Fabric | private | Data Integrity, confidentiality, data privacy | permissioned |
| S5 | IOT | Ethereum | public, private | Integrity, confidentiality, architectural security | permissioned |
| S6 | EHR | Ethereum | public | Security, data integrity | permissioned |
| S7 | Multi-cloud application | NA | NA | Authentication, security performance | NA |
| S8 | Cloud application | Ethereum | public | Forensic security analysis, architectural security | permissioned |
| S9 | Cloud-based application | Ethereum | public | NA | Permissionless |
| S10 | Service Orchestration | Ethereum and Hyperledger | public, private | Integrity, confidentiality | permissioned |
| S11 | Multi-cloud system | - | Consortium blockchain | Confidentiality, transparency, integrity | permissioned |
| S12 | API based Application | Ethereum | private, public | Authentication, Data Integrity | permissioned |
| S13 | Oracle | Oracle | private | Integrity, transparency | permissioned |
| S14 | IOT | Ethereum | private, public | Authenticity, integrity, performance | Permissioned |
| S15 | Bifröst application | Ethereum | private | Integrity, semantic security | permissioned |
| S16 | SLA multi-cloud application | NA | NA | Interoperability, fault tolerance and scalability | permissioned |
| S17 | SSI | Hyperledger Fabric | public, private | Integrity, confidentiality | permissioned |
| S18 | Multi-cloud application | Ethereum | public, private | Confidentiality, data integrity | permissioned |
| S19 | Healthcare | - | Consortium blockchain | Confidentiality, integrity, and security features | permissioned |
| S20 | Service orchestration | NA | NA | Confidentiality, security, and compliance | NA |
| S21 | IOT | Local Blockchain | private | Transparency, data integrity | permissioned |
| S22 | Application based on container | Ethereum | private | Integrity, security assets | permissioned |
| S23 | Northbound interface | Hyperledger fabric | private | Authentication, authorization, confidentiality | permissionless |
| S24 | Multi-Cloud Architectures | NA | private | Audit, automation, secure transaction | NA |
| Security Dimensions | Typical Risk in Multi-Cloud Systems | Blockchain Contribution | Remaining Gap Addressed by SOC-LLM |
|---|---|---|---|
| Architecture | Fragmented trust boundaries, workload placement risk, lack of unified audit | Immutable topology evidence, trusted service registry, decentralized trust anchors | Detect hidden multi-stage patterns and reason over cross-cloud context |
| API (Application Programming Interface) security | Token abuse, weak authorization, excessive privileges, API (Application Programming Interface) call manipulation | Signed API (Application Programming Interface) transactions, smart-contract audit trails, decentralized API (Application Programming Interface) verification | Correlate API (Application Programming Interface) sequences, explain suspicious behavior and recommend containment |
| IAM (Identity and Access Management)/authentication | Credential compromise, role abuse, federation weaknesses, identity theft | Decentralized identity, verifiable credentials, auditable access decisions | Identify anomalous identity behavior and explain why access is suspicious |
| Orchestration and automation | Compromised CI/CD (Continuous Integration and Continuous Delivery/Deployment), malicious infrastructure-as-code, container drift | Trusted workflow records, policy enforcement, tamper-resistant deployment logs | Detect orchestration drift and investigate tool-chain anomalies |
| SLA (Service Level Agreement) management | Unverifiable downtime, performance disputes, responsibility ambiguity | Smart contracts for SLA (Service Level Agreement) evidence and violation records | Predict SLA (Service Level Agreement) degradation and correlate it with incidents |
| Cybersecurity compliance | Fragmented evidence, privacy risks, incomplete auditability | Immutable evidence chain, access traceability, accountability | Mapping technical evidence to compliance requirements and generate audit-ready explanations |
| Approach | Detection | Explanation | Evidence Integrity | Response Support | Main Limitation |
|---|---|---|---|---|---|
| Blockchain only | Low to medium | Low | High | Low | Records events but does not interpret attack intent |
| SIEM/rules only | Medium | Medium | Medium | Medium | High false positives and limited cross-cloud reasoning |
| ML anomaly detection only | Medium to high | Low | Low to medium | Low | Black-box decisions and weak forensic evidence |
| LLM only | Medium | High | Low | Medium | Hallucination and lack of trusted evidence |
| SOC-LLM + ML + blockchain | High potential | High | High | High | Requires governance, validation and benchmarking |
| Agent | Main Role | Input | Output |
|---|---|---|---|
| Detection agent | Classify and prioritize suspicious events | Alerts, anomaly scores, SIEM events | Initial incident hypothesis |
| Correlation agent | Link events across clouds and time windows | Logs, identities, assets, network flows | Attack timeline and related evidence |
| RAG threat-intelligence agent | Retrieve grounded context | Incident hypothesis and indicators | Relevant tactics, vulnerabilities and playbooks |
| Blockchain evidence agent | Verify evidence integrity | Log hash, transaction ID, smart contract state | Evidence validation report |
| Explanation agent | Generate analyst-readable reasoning | Correlated events and verified evidence | Incident explanation and confidence |
| Response planner | Recommend containment and recovery actions | Incident severity and business context | SOAR-ready response plan |
| Oversight agent | Control hallucination and contradiction | All agent outputs | Approved, rejected or revised investigation |
| Challenge | Risk | Mitigation Strategy |
|---|---|---|
| LLM hallucination | Incorrect explanations or unsupported recommendations | Evidence-grounded RAG, oversight agent, citation of log IDs, human validation |
| Data privacy | Sensitive logs exposed to LLM or third-party services | Local/private LLMs, redaction, access controls, on-chain hashes only |
| Real-time scalability | High latency from multi-agent reasoning and blockchain writes | Fast/slow pipeline, model distillation, selective on-chain anchoring, batching |
| Dataset scarcity | Limited labeled multi-cloud attack data | Synthetic log generation, cyber range simulation, weak supervision, transfer learning |
| Interoperability | Different cloud logs, IAM models and APIs | Common event schema, adapters, Open Telemetry-like normalization |
| Explainability | Black-box ML and complex agent traces | Structured incident narratives, feature attribution, timeline visualization |
| Governance | Uncontrolled automation may cause business disruption | Approval workflows, risk-based automation, rollback procedures |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Abbass Ahmat, A.K.; Chaoui, H. Intelligent Attack Detection in Blockchain-Enabled Multi-Cloud Systems: A Systematic Review and SOC-LLM-Augmented Architecture Proposal. Computers 2026, 15, 456. https://doi.org/10.3390/computers15070456
Abbass Ahmat AK, Chaoui H. Intelligent Attack Detection in Blockchain-Enabled Multi-Cloud Systems: A Systematic Review and SOC-LLM-Augmented Architecture Proposal. Computers. 2026; 15(7):456. https://doi.org/10.3390/computers15070456
Chicago/Turabian StyleAbbass Ahmat, Adam Koty, and Habiba Chaoui. 2026. "Intelligent Attack Detection in Blockchain-Enabled Multi-Cloud Systems: A Systematic Review and SOC-LLM-Augmented Architecture Proposal" Computers 15, no. 7: 456. https://doi.org/10.3390/computers15070456
APA StyleAbbass Ahmat, A. K., & Chaoui, H. (2026). Intelligent Attack Detection in Blockchain-Enabled Multi-Cloud Systems: A Systematic Review and SOC-LLM-Augmented Architecture Proposal. Computers, 15(7), 456. https://doi.org/10.3390/computers15070456

