Home / Current Issue / Paper 1712272
Bridging the Cybersecurity Divide: A Systematic Review of AI And Lightweight Monitoring for Resource-Constrained Institutions
Subject area: Science,Engineering and Technology · Area of research: Lightweight Network Monitoring
Abstract
The digital transformation has exacerbated a critical cybersecurity divide, systematically excluding low-resource institutions for example schools, NGOs, and SMEs from modern network protection due to profound constraints in budget, hardware, and expertise. While research in network monitoring has advanced, featuring sophisticated AI for anomaly detection and cloud-based orchestration, its applicability to constrained environments remains critically underexplored. This study conducts a systematic literature review of 150 peer-reviewed works (2018-2025) to map the state-of-the-art and evaluate its alignment with the needs of low-resource settings. Our analysis, structured across four thematic areas namely AI Anomaly Detection, Lightweight Monitoring, Cloud Integration, and Configuration Management reveals a pervasive convergence gap. We identify that research excels in technological silos but fails at their intersection: AI models are computationally prohibitive, lightweight solutions lack adaptive intelligence, cloud frameworks assume stable connectivity, and configuration tools operate in isolation. This siloed progression creates a landscape where solutions are either too bulky, too simple, too cloud-dependent, or too complex for practical deployment in target institutions. The primary contribution of this review is the articulation of four core requirements for a new holistic paradigm: (1) Resource-Aware AI, (2) Progressive Intelligence, (3) Intermittent-Cloud Resilience, and (4) a Unified Management Plane. In direct response, we propose the development of a lightweight, AI-cloud-integrated platform as a direct path forward. This review synthesizes a fragmented field and provides a definitive research agenda aimed at bridging the cybersecurity divide through architectural convergence.
Keywords
Cybersecurity Divide, Resource-Constrained Networks, Lightweight Network Monitoring, AI Anomaly Detection, Cloud-Edge Integration
References
[1] W. J. Triplett, “Digital Divide in Cybersecurity,” Cybersecurity and Innovation Technology Journal, vol. 3, no. 1, pp. 1–8, 2025,
[2] L. Huey and L. Ferguson, “Another Digital Divide: Cybersecurity in Indigenous Communities,” CrimRxiv, Feb. 2022, 10.21428/cb6ab371.bbf05cbc.
[3] F. M. Anis, M. Alabdullatif, S. Aljbli, M. Hammoudeh, and S. Member, “Date of publication xxxx 00, 0000, date of current version xxxx 00, 0000. A Survey on the Applications of Deep Learning in Network Intrusion Detection Systems to Enhance Network Securit y”, 10.1109/ACCESS.2017.
[4] N. R. Al-Milli and Y. A. Al-Khassawneh, “Intrusion Detection System using CNNs and GANs,” WSEAS Transactions on Computer Research, vol. 12, pp. 281–290, 2024, 10.37394/232018.2024.12.27.
[5] P. Krishnan, K. Jain, A. Aldweesh, P. Prabu, and R. Buyya, “OpenStackDP: a scalable network security framework for SDN-based OpenStack cloud infrastructure,” Journal of Cloud Computing, vol. 12, no. 1, Dec. 2023, 10.1186/s13677-023-00406-w.
[6] P. F. Saura, J. M. Bernabé Murcia, E. G. de la Calera Molina, A. M. Zarca, J. B. Bernabé, and A. F. Skarmeta Gómez, “Federated Network Intelligence Orchestration for Scalable and Automated FL-Based Anomaly Detection in B5G Networks,” Computers, Materials and Continua, vol. 80, no. 1, pp. 163–193, 2024,
[7] E. Gamess and S. Hernandez, “Performance Evaluation of SNMPv1/2c/3 using Different Security Models on Raspberry Pi.” [Online]. Available: www.ijacsa.thesai.org
[8] F. S. Bruschetti, J. Guevara, M. C. Abeledo, and D. A. Priano, “An Empirical Evaluation of Automated Configuration Tools for Software- Defined Networking: A Usability and Performance Perspective,” Ingenierie des Systemes d’Information, vol. 28, no. 5, pp. 1127–1134, 2023,
[9] K. Dietz et al., “The Missing Link in Network Intrusion Detection: Taking AI/ML Research Efforts to Users,” IEEE Access, vol. 12, pp. 79815–79837, 2024, 10.1109/ACCESS.2024.3406939.
[10] N. R. Haddaway, M. J. Page, C. C. Pritchard, and L. A. McGuinness, “PRISMA2020: An R package and Shiny app for producing PRISMA 2020-compliant flow diagrams, with interactivity for optimised digital transparency and Open Synthesis,” Campbell Systematic Reviews, vol. 18, no. 2, p. e1230, Jun. 2022,
[11] C. Tselios, I. Politis, and C. Xenakis, “Improving Network, Data and Application Security for SMEs,” in ACM International Conference Proceeding Series, Association for Computing Machinery, Aug. 2022. 10.1145/3538969.3544426.
[12] V. S. Rao, R. Balakrishna, Y. A. B. El-Ebiary, P. Thapar, K. A. Saravanan, and S. R. Godla, “AI Driven Anomaly Detection in Network Traffic Using Hybrid CNN-GAN,” Journal of Advances in Information Technology, vol. 15, no. 7, pp. 886 –895, 2024, 10.12720/jait.15.7.886-895.
[13] G. Nguyen, S. Dlugolinsky, V. Tran, and A. Lopez Garcia, “Deep learning for proactive network monitoring and security protection,” IEEE Access, vol. 8, pp. 19696–19716, 2020,
[14] O. Lytvyn and G. Nguyen, “Secure Federated Learning for Multi -Party Network Monitoring,” IEEE Access, vol. 12, pp. 163262–163284, 2024, 10.1109/ACCESS.2024.3486810.
[15] M. Lyu, H. Habibi Gharakheili, and V. Sivaraman, “A Survey on Enterprise Network Security: Asset Behavioral Monitoring and Distributed Attack Detection,” IEEE Access, vol. 12, pp. 89363–89383, 2024, 10.1109/ACCESS.2024.3419068.
[16] M. A. Paracha, S. U. Jamil, K. Shahzad, M. A. Khan, and A. Rasheed, “Leveraging AI for Network Threat Detection—A Conceptual Overview,” Electronics (Switzerland), vol. 13, no. 23, Dec. 2024, 10.3390/electronics13234611.
[17] M. N. Mowla, N. Mowla, A. F. M. S. Shah, K. M. Rabie, and T. Shongwe, “Internet of Things and Wireless Sensor Networks for Smart Agriculture Applications: A Survey,” IEEE Access, vol. 11, pp. 145813–145852, 2023, 10.1109/ACCESS.2023.3346299.
[18] M. Abranches, O. Michel, E. Keller, and S. Schmid, “Efficient Network Monitoring Applications in the Kernel with eBPF and XDP,” in 2021 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN), IEEE, 2021, pp. 28–34.
[19] I. Mutambik, “An Efficient Flow-Based Anomaly Detection System for Enhanced Security in IoT Networks,” Sensors, vol. 24, no. 22, Nov. 2024,
[20] G. Ingletto, N. Xiong, M. L. Ortiz, T. Markovic, A. Egeberg, and P. E. Strandberg, “ANOMALY DETECTION FOR NETWORK TRAFFIC IN A RESOURCE CONSTRAINED ENVIRONMENT,” 2023. [Online]. Available: https://github.com/westermo.
[21] G. AL Mukhaini, M. Anbar, S. Manickam, T. A. Al-Amiedy, and A. Al Momani, “A systematic literature review of recent lightweight detection approaches leveraging machine and deep learning mechanisms in Internet of Things networks,” Jan. 01, 2024, King Saud bin Abdulaziz University. 10.1016/j.jksuci.2023.101866.
[22] A. Mwotil, T. Anderson, B. Kanagwa, T. Stavrinos, and E. Bainomugisha, “LowPaxos: State Machine Replication for Low Resource Settings,” IEEE Access, vol. 12, pp. 91272– 91288, 2024, 10.1109/ACCESS.2024.3421582.
[23] Y. Chevalier, F. Fenzl, M. Kolomeets, R. Rieke, A. Chechulin, and C. Krauss, “CYBERATTACK DETECTION in VEHICLES USING CHARACTERISTIC FUNCTIONS, ARTIFICIAL NEURAL NETWORKS and VISUAL ANALYSIS,” Informatics and Automation, vol. 20, no. 4, pp. 845–868, Aug. 2021,
[24] N. Cai, Z. Deng, and H. Wang, “An Intelligent Data Flow Security Strategy Model of Cloud- Network Integration,” in Communications in Computer and Information Science, Springer Science and Business Media Deutschland GmbH, 2022, pp. 3–27. 19-8285-9_1.
[25] D. Hastbacka et al., “Dynamic Edge and Cloud Service Integration for Industrial IoT and Production Monitoring Applications of Industrial Cyber-Physical Systems,” IEEE Trans Industr Inform, vol. 18, no. 1, pp. 498– 508, Jan. 2022, 10.1109/TII.2021.3071509.
[26] E. Bainomugisha and A. Mwotil, “Crane Cloud: A resilient multi-cloud service abstraction layer for resource-constrained settings,” Dev Eng, vol. 7, Jan. 2022, 10.1016/j.deveng.2022.100102.
[27] M. Fuentes-Garcia, J. Camacho, and G. Macia- Fernandez, “Present and Future of Network Security Monitoring,” IEEE Access, vol. 9, pp. 112744–112760, 2021, 10.1109/ACCESS.2021.3067106.
[28] I. Pelle and A. Gulyás, “An extensible automated failure localization framework using NetKAT, Felix, and SDN traceroute,” Future Internet, vol. 11, no. 5, May 2019, 10.3390/fi11050107.
[29] H. Okita, M. Yoshizawa, K. Uehara, K. Mizuno, T. Tarui, and K. Naono, “Proposal of Virtual Network Configuration Acquisition Function for Data Center Operations and Management System.”
How to cite this paper
@article{1712272,
author = {Mugerwa Joseph, Odo Francis Ikechukwu, Kitumba David},
title = {Bridging the Cybersecurity Divide: A Systematic Review of AI And Lightweight Monitoring for Resource-Constrained Institutions},
journal = {Iconic Research And Engineering Journals},
year = {2025},
volume = {9},
number = {5},
pages = {1884-1894},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1712272.pdf},
abstract = {The digital transformation has exacerbated a critical cybersecurity divide, systematically excluding low-resource institutions for example schools, NGOs, and SMEs from modern network protection due to profound constraints in budget, hardware, and expertise. While research in network monitoring has advanced, featuring sophisticated AI for anomaly detection and cloud-based orchestration, its applicability to constrained environments remains critically underexplored. This study conducts a systematic literature review of 150 peer-reviewed works (2018-2025) to map the state-of-the-art and evaluate its alignment with the needs of low-resource settings. Our analysis, structured across four thematic areas namely AI Anomaly Detection, Lightweight Monitoring, Cloud Integration, and Configuration Management reveals a pervasive convergence gap. We identify that research excels in technological silos but fails at their intersection: AI models are computationally prohibitive, lightweight solutions lack adaptive intelligence, cloud frameworks assume stable connectivity, and configuration tools operate in isolation. This siloed progression creates a landscape where solutions are either too bulky, too simple, too cloud-dependent, or too complex for practical deployment in target institutions. The primary contribution of this review is the articulation of four core requirements for a new holistic paradigm: (1) Resource-Aware AI, (2) Progressive Intelligence, (3) Intermittent-Cloud Resilience, and (4) a Unified Management Plane. In direct response, we propose the development of a lightweight, AI-cloud-integrated platform as a direct path forward. This review synthesizes a fragmented field and provides a definitive research agenda aimed at bridging the cybersecurity divide through architectural convergence.},
keywords = {Cybersecurity Divide, Resource-Constrained Networks, Lightweight Network Monitoring, AI Anomaly Detection, Cloud-Edge Integration},
month = {November},
doi = {https://doi.org/10.64388/IREV9I5-1712272}
}