PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
February 24, 2026Cybersecurity3 citationsOpen Access

Cross: a cloud-native approach to automated remediation and self-healing in cyber-physical systems

OJObinna JohnphillASAli Safaa SadiqOKOmprakash Kaiwartya

Key Points

  • The aim is to present CROSS, a system designed to enhance self-healing and remediation in cyber-physical systems.
  • Developed a cloud-native, cross-platform approach for automated remediation.
  • Leveraged a policy-driven remediation layer for tailored recovery actions.
  • Employed Prometheus-based observability for monitoring anomalies and actions.
  • Focused on operational anomalies with future considerations for cybersecurity.
  • Demonstrated measurable reductions in mean time to recovery (MTTR).
  • Showed improvements in anomaly containment across diverse CPS environments.
  • Established a connection between anomaly detection and active cyber defense.

Abstract

Abstract Cyber-Physical Systems (CPS) operate in increasingly complex and security-critical environments where system faults, misconfigurations, and cyberattacks can compromise safety, availability, and operational integrity. This paper presents CROSS (Cross-platform Remediation and Observability Self-Healing System), a cloud-native, cross-platform approach that extends the self-healing paradigm beyond anomaly detection to encompass autonomous, security-aware remediation. Building upon the Log Intelligence and Self-Healing System ( LISH ) (Johnphill et al. 2023a), which utilised CountVectorizer and Multinomial Naive Bayes ( MNB ) for log-based anomaly classification, CROSS introduces a policy-driven remediation layer that executes context-specific recovery actions such as service restarts, system updates, device reboots, and configuration enforcement across Android, Linux, macOS, and Windows. Prometheus-based observability (Pai and Srinivas 2024) provides fine-grained telemetry on anomalies and remedial actions, enabling continuous monitoring, auditability, and adaptive security governance. Experimental evaluation demonstrates measurable reductions in mean time to recovery (MTTR) and improvements in anomaly containment and resilience across heterogeneous CPS environments. Although CROSS includes mechanisms that are applicable to cybersecurity scenarios, the present evaluation focuses on operational anomalies rather than explicit attack-induced behaviours. Accordingly, its cybersecurity relevance is framed as an architectural capability, with empirical security benchmarking identified as future work. The proposed approach bridges the gap between anomaly detection and active cyber defence, embedding explainable, automated remediation within the operational lifecycle of CPS.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Johnphill et al. (2026) studied this question.

synapsesocial.com/papers/699d3ff8de8e28729cf64da6https://doi.org/10.1186/s42400-026-00549-8
Ask AI
Helpful
Bookmark
Share
View Full Paper