PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
February 24, 2026Cybersecurity3 citationsOpen Access

Cross: a cloud-native approach to automated remediation and self-healing in cyber-physical systems

OJObinna JohnphillASAli Safaa SadiqOKOmprakash Kaiwartya

Key Points

  • The aim is to present CROSS, a system designed to enhance self-healing and remediation in cyber-physical systems.
  • Developed a cloud-native, cross-platform approach for automated remediation.
  • Leveraged a policy-driven remediation layer for tailored recovery actions.
  • Employed Prometheus-based observability for monitoring anomalies and actions.
  • Focused on operational anomalies with future considerations for cybersecurity.
  • Demonstrated measurable reductions in mean time to recovery (MTTR).
  • Showed improvements in anomaly containment across diverse CPS environments.
  • Established a connection between anomaly detection and active cyber defense.

Abstract

Abstract Cyber-Physical Systems (CPS) operate in increasingly complex and security-critical environments where system faults, misconfigurations, and cyberattacks can compromise safety, availability, and operational integrity. This paper presents CROSS (Cross-platform Remediation and Observability Self-Healing System), a cloud-native, cross-platform approach that extends the self-healing paradigm beyond anomaly detection to encompass autonomous, security-aware remediation. Building upon the Log Intelligence and Self-Healing System ( LISH ) (Johnphill et al. 2023a), which utilised CountVectorizer and Multinomial Naive Bayes ( MNB ) for log-based anomaly classification, CROSS introduces a policy-driven remediation layer that executes context-specific recovery actions such as service restarts, system updates, device reboots, and configuration enforcement across Android, Linux, macOS, and Windows. Prometheus-based observability (Pai and Srinivas 2024) provides fine-grained telemetry on anomalies and remedial actions, enabling continuous monitoring, auditability, and adaptive security governance. Experimental evaluation demonstrates measurable reductions in mean time to recovery (MTTR) and improvements in anomaly containment and resilience across heterogeneous CPS environments. Although CROSS includes mechanisms that are applicable to cybersecurity scenarios, the present evaluation focuses on operational anomalies rather than explicit attack-induced behaviours. Accordingly, its cybersecurity relevance is framed as an architectural capability, with empirical security benchmarking identified as future work. The proposed approach bridges the gap between anomaly detection and active cyber defence, embedding explainable, automated remediation within the operational lifecycle of CPS.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Johnphill et al. (2026) studied this question.

synapsesocial.com/papers/699d3ff8de8e28729cf64da6https://doi.org/10.1186/s42400-026-00549-8
Ask AI
Helpful
Bookmark
Share
View Full Paper

Also Consider

Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context:

  1. 1MoniLog: An Automated Log-Based Anomaly Detection System for Cloud Computing Infrastructures2021 · 34 citations
  2. 2Comprehensive Monitoring and Observability with Jenkins and Grafana: A Review of Integration Strategies, Best Practices, and Emerging Trends2023 · 6 citations
  3. 3Case Study Based Investigation on Self-Healing Cloud Deployments for Edge-Based Software Development2024 · 3 citations
  4. 4An Intelligent Approach to Automated Operating Systems Log Analysis for Enhanced Security2024 · 4 citations
  5. 5Proactive monitoring and security in cloud infrastructure: leveraging tools like Prometheus, Grafana, and HashiCorp Vault for Robust DevOps Practices2024 · 9 citations