Intelligent Attack Detection in Blockchain-Enabled Multi-Cloud Systems: A Systematic Review and SOC-LLM-Augmented Architecture Proposal
Abstract
This paper presents a systematic literature review examining how blockchain technologies can enhance the security and performance of multi-cloud systems. Multi-cloud architectures offer resilience, scalability, and flexibility; however, they also pose complex security challenges related to APIs, service-level agreements (SLAs), orchestration, and authentication. The promise of blockchain technology to improve the security and transparency of numerous applications, including cloud storage systems, has attracted considerable attention in recent years. Much research has focused on decentralized storage in cloud environments, spanning supply chains, FinTech, healthcare, and education. Still, the integration of blockchain with the cloud and its potential to enhance security and performance warrant an in-depth study. Using the PRISMA methodology, a structured search was conducted across six major scientific databases, including IEEE, ACM Digital Library, ScienceDirect, Scopus, Web of Science, and IJIMAI. Twenty-four primary papers published between 2019 and 2025 were selected for analysis after clear inclusion and exclusion criteria were applied. This review examines the security dimensions in multi-cloud environments—architectural vulnerabilities, API security, authentication, orchestration and automation vulnerabilities, SLAs, and cybersecurity compliance issues—in relation to blockchain technology. Based on the identified gaps, we propose a SOC-LLM-augmented security architecture that integrates blockchain-based evidence integrity, statistical anomaly detection, machine learning, large language models, and autonomous AI agents to enable intelligent attack detection and response. The proposed framework introduces specialized agents for detection, correlation, threat intelligence retrieval, blockchain evidence validation, explanation generation, and response planning. The analysis shows that integrating SOC-LLM capabilities with blockchain can move multi-cloud security from passive auditability toward proactive, explainable, and human-in-the-loop cyber defense. Finally, this paper discusses open challenges, including LLM hallucination, data scarcity, real-time scalability, evaluation standardization, and trustworthy deployment in critical multi-cloud infrastructures. The study’s conclusion highlights research gaps and suggests future lines of inquiry concerning scalable blockchain architectures and the incorporation of AI for proactive cloud security monitoring.