<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xml:lang="en" article-type="research-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">JCS</journal-id>
<journal-id journal-id-type="nlm-ta">JCS</journal-id>
<journal-id journal-id-type="publisher-id">JCS</journal-id>
<journal-title-group>
<journal-title>Journal of Cyber Security</journal-title>
</journal-title-group>
<issn pub-type="epub">2579-0064</issn>
<issn pub-type="ppub">2579-0072</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">70952</article-id>
<article-id pub-id-type="doi">10.32604/jcs.2025.070952</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>An Intelligent Zero Trust Architecture Model for Mitigating Authentication Threats and Vulnerabilities in Cloud-Based Services</article-title>
<alt-title alt-title-type="left-running-head">An Intelligent Zero Trust Architecture Model for Mitigating Authentication Threats and Vulnerabilities in Cloud-Based Services</alt-title>
<alt-title alt-title-type="right-running-head">An Intelligent Zero Trust Architecture Model for Mitigating Authentication Threats and Vulnerabilities in Cloud-Based Services</alt-title>
</title-group>
<contrib-group>
<contrib id="author-1" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Mony</surname><given-names>Victor Otieno</given-names></name><email>victor@rcadventist.org</email></contrib>
<contrib id="author-2" contrib-type="author">
<name name-style="western"><surname>Ikoha</surname><given-names>Anselemo Peters</given-names></name></contrib>
<contrib id="author-3" contrib-type="author">
<name name-style="western"><surname>Maroko</surname><given-names>Roselida O.</given-names></name></contrib>
<aff id="aff-1"><institution>Department of Information Technology, School of Computing &#x0026; Informatics, Kibabii University</institution>, <addr-line>Bungoma, 50200</addr-line>, <country>Kenya</country></aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><label>&#x002A;</label>Corresponding Author: Victor Otieno Mony. Email: <email>victor@rcadventist.org</email></corresp>
</author-notes>
<pub-date date-type="collection" publication-format="electronic">
<year>2025</year>
</pub-date>
<pub-date date-type="pub" publication-format="electronic">
<day>30</day><month>09</month><year>2025</year>
</pub-date>
<volume>7</volume>
<issue>1</issue>
<fpage>395</fpage>
<lpage>415</lpage>
<history>
<date date-type="received">
<day>28</day>
<month>7</month>
<year>2025</year>
</date>
<date date-type="accepted">
<day>27</day>
<month>8</month>
<year>2025</year>
</date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2025 The Authors.</copyright-statement>
<copyright-year>2025</copyright-year>
<copyright-holder>Published by Tech Science Press.</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_JCS_70952.pdf"></self-uri>
<abstract>
<p>The widespread adoption of Cloud-Based Services has significantly increased the surface area for cyber threats, particularly targeting authentication mechanisms, which remain among the most vulnerable components of cloud security. This study aimed to address these challenges by developing and evaluating an Intelligent Zero Trust Architecture model tailored to mitigate authentication-related threats in Cloud-Based Services environments. Data was sourced from public repositories, including Kaggle and the National Institute for Standards and Technology MITRE Corporation&#x2019;s Adversarial Tactics, Techniques, &#x0026; Common Knowledge (ATT&#x0026;CK) framework. The study utilized two trust signals: Behavioral targeting system users and Contextual targeting system devices. Based on the trust signals, two machine learning models&#x2014;Keystroke Dynamics and Device Location&#x2014;were developed using Binary Logistic Regression, achieving a combined average accuracy of 80.63%, with a residual ineffectiveness rate of 19.37%. The Intelligent Zero-Trust Architecture Threat Mitigation Model was introduced to reclassify threat severity scores, resulting in the downgrading of all authentication threats to Low Severity, demonstrating a mitigation effectiveness exceeding 80%. This research contributes to the field of cybersecurity by presenting a validated, intelligent, and context-aware Intelligent Zero-Trust Architecture model capable of enhancing identity and access management in dynamic cloud environments. The findings offer actionable insights for cloud architects, cybersecurity professionals, and policymakers aiming to strengthen trust, reduce attack surfaces, and improve threat resilience across digital infrastructure.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>Cloud-based services</kwd>
<kwd>zero trust architecture</kwd>
<kwd>intelligent zero trust architecture</kwd>
<kwd>cloud computing</kwd>
<kwd>cloud authentication</kwd>
<kwd>machine learning</kwd>
<kwd>binary logistics regression</kwd>
<kwd>loss function</kwd>
<kwd>holdout validation</kwd>
<kwd>confusion matrix</kwd>
<kwd>precision rates</kwd>
<kwd>negative predictive value</kwd>
</kwd-group>
</article-meta>
</front>
<body>
<sec id="s1">
<label>1</label>
<title>Introduction</title>
<p>Zero Trust Architecture (ZTA) has emerged as a transformative framework in modern cybersecurity, particularly for cloud-based environments where traditional perimeter-based security models are insufficient. Rooted in the principle of &#x201C;never trust, always verify,&#x201D; ZTA mandates continuous validation of users, devices, and network behavior before granting access to resources [<xref ref-type="bibr" rid="ref-1">1</xref>]. ZTA is a promising paradigm to counter Cloud-based Services (CBS) authentication challenges because it enforces strict access controls, continuous verification, and the principles of least privilege, while providing enhanced visibility and analytics for improved decision-making across cloud environments [<xref ref-type="bibr" rid="ref-2">2</xref>]. Unlike perimeter-based models, ZTA treats every access request as untrusted by default, thus offering a more granular and dynamic approach to cloud security. Zero-trust is growing in favor in cloud environments as a means through which unauthorized access can be mitigated. Thus, it enables a more successful prevention mechanism against advanced assaults [<xref ref-type="bibr" rid="ref-3">3</xref>]. This paradigm shift addresses the increasing sophistication of cyber threats and the vulnerabilities arising from distributed systems, remote work, and hybrid cloud architectures.</p>
<p>Cloud systems are particularly vulnerable due to their shared and complex systems [<xref ref-type="bibr" rid="ref-3">3</xref>]. CBS enables users to interact directly with cloud-based applications, making it especially vulnerable to attacks that exploit weak authentication mechanisms [<xref ref-type="bibr" rid="ref-4">4</xref>,<xref ref-type="bibr" rid="ref-5">5</xref>]. Researchers have proposed emerging solutions, including decentralized identity protocols, blockchain-based authentication, and lightweight key exchange protocols [<xref ref-type="bibr" rid="ref-6">6</xref>,<xref ref-type="bibr" rid="ref-7">7</xref>]. Nonetheless, many of these innovations face practical limitations when implemented in the dynamic, distributed cloud environments. For example, while blockchain offers immutability, it does not address the problem of real-time verification of user behavior.</p>
<p>The Kerberos protocol used in distributed authentication systems relies on the Key Distribution Center (KDC) and the Key Distribution System (KDS), which utilize public keys to strengthen data confidentiality and secure messages. Authentication in the protocol Kerberos is done through a unique ticket system. The tickets are granted through a KDC hosted on third-party servers to provide scalability [<xref ref-type="bibr" rid="ref-8">8</xref>,<xref ref-type="bibr" rid="ref-9">9</xref>].</p>
<p>The Kerberos protocol relies on symmetric key encryption but is vulnerable to dictionary and brute-force attacks if weak passwords are used [<xref ref-type="bibr" rid="ref-8">8</xref>]. Symmetric keys used in Kerberos also lead to the likelihood of data breaches when the KDC is compromised. Further, Kerberos provides the public key at both ends of data transit, and this is a vulnerability that can be exploited using means such as Denial of Service Attacks. Kerberos also relies on trusted third-party servers, which may lead to insider attacks and cause serious data breaches. A dictionary attack on the Kerberos protocol can steal passwords by interrupting data flow. A compromise in the tickets by threat actors leads to a compromise in the KDC. This is because Kerberos utilizes symmetric encryption, where a single unique key is utilized, and this increases its vulnerability should the key be compromised. Further, in symmetric key cryptography, the algorithms used, such as Advanced Encryption Standard (AES), are increasingly becoming vulnerable in the face of quantum computing threats [<xref ref-type="bibr" rid="ref-8">8</xref>,<xref ref-type="bibr" rid="ref-9">9</xref>].</p>
<p>Likewise, public key infrastructure (PKI)-based authentication often requires physical tokens or one-time password generators, posing usability and manageability challenges [<xref ref-type="bibr" rid="ref-10">10</xref>]. These vulnerabilities highlight the inadequacy of traditional perimeter-based security models, which often assume implicit trust once access is granted. In response to these threats and vulnerabilities, there has been a shift toward stronger authentication mechanisms, such as two-factor authentication (2FA), multi-factor authentication (MFA), and behavioral biometrics [<xref ref-type="bibr" rid="ref-11">11</xref>]. The emergence of quantum computing further exacerbates the situation by threatening to render many of today&#x2019;s encryption algorithms obsolete [<xref ref-type="bibr" rid="ref-3">3</xref>]. The crypto market disruptions of 2022 underscored the urgency of rethinking foundational security mechanisms [<xref ref-type="bibr" rid="ref-12">12</xref>]. Insider threats and third-party risks compound the problem, as trusted users may become inadvertent attack vectors by leaking credentials or bypassing controls [<xref ref-type="bibr" rid="ref-13">13</xref>]. Against this backdrop, Zero Trust Architecture (ZTA) has gained prominence as a paradigm shift in cybersecurity.</p>
<p>Research literature reveals a decisive transition from traditional perimeter-based security models to identity-centric frameworks such as Zero Trust Architecture (ZTA). This shift is motivated by the inadequacy of conventional security measures to address modern cyber threats in cloud-based services. ZTA emphasizes continuous verification of both user identity and device posture, rejecting the notion of implicit trust within internal networks. As a result, organizations are adopting ZTA to minimize attack surfaces and enforce context-aware access control [<xref ref-type="bibr" rid="ref-14">14</xref>,<xref ref-type="bibr" rid="ref-15">15</xref>].</p>
<p>Another notable trend is the integration of Artificial Intelligence (AI) and Machine Learning (ML) into ZTA frameworks. Intelligent security models that utilize behavioral analytics and real-time threat detection are being developed to enhance the adaptability and precision of access decisions [<xref ref-type="bibr" rid="ref-16">16</xref>]. These systems dynamically calculate trust scores based on various contextual inputs, including user behavior anomalies, device health, and location data. Furthermore, behavioral biometrics such as keystroke dynamics are increasingly being explored to improve the reliability of user authentication [<xref ref-type="bibr" rid="ref-17">17</xref>].</p>
<p>Multi-cloud and federated environments are also influencing the evolution of ZTA implementations. With cloud services becoming more distributed, organizations face new challenges in enforcing consistent security policies across heterogeneous platforms. Consequently, researchers are focusing on federated learning, decentralized policy engines, and cross-domain trust models to ensure robust authentication across complex cloud ecosystems [<xref ref-type="bibr" rid="ref-18">18</xref>].</p>
<p>Despite these advancements, several gaps persist in the literature. First, there is a lack of empirical validation for most Intelligent Zero Trust Architecture (IZTA) models. Many proposed frameworks remain conceptual or are only tested through limited simulations, failing to demonstrate their effectiveness in real-world SaaS or hybrid cloud environments [<xref ref-type="bibr" rid="ref-19">19</xref>]. This gap limits the generalizability and practical application of existing models.</p>
<p>Secondly, the underutilization of multi-modal trust signals is a recurring limitation. Most ZTA models rely on a narrow range of indicators&#x2014;such as static credentials, IP reputation, or device fingerprints&#x2014;without integrating more diverse behavioral and environmental data. The failure to incorporate factors like keystroke dynamics, geo-location, user intent, and biometric feedback reduces the models&#x2019; responsiveness to nuanced threat vectors [<xref ref-type="bibr" rid="ref-20">20</xref>].</p>
<p>Another critical gap involves the explainability of AI-driven access decisions. Many ML-based ZTA models operate as &#x201C;black boxes,&#x201D; making it difficult for system administrators to understand why access is granted or denied. This lack of transparency raises compliance concerns and impairs user trust in the system [<xref ref-type="bibr" rid="ref-3">3</xref>,<xref ref-type="bibr" rid="ref-21">21</xref>]. In addition, performance challenges such as computational latency and resource overhead further complicate real-time deployment of intelligent authentication mechanisms in high-volume environments [<xref ref-type="bibr" rid="ref-16">16</xref>]. <xref ref-type="table" rid="table-1">Table 1</xref> gives a summary of the identified research gaps in the literature:</p>
<table-wrap id="table-1">
<label>Table 1</label>
<caption>
<title>Identified knowledge gaps and the study&#x2019;s strategic response</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
</colgroup>
<thead>
<tr>
<th align="center">Theme</th>
<th align="center">Author(s)</th>
<th align="center">Key findings</th>
<th align="center">Identified gap</th>
<th align="center">How the study filled the gap</th>
</tr>
</thead>
<tbody>
<tr>
<td><bold>Lack of empirical validation</bold></td>
<td>Wei (2023) [<xref ref-type="bibr" rid="ref-19">19</xref>]</td>
<td>Most Intelligent Zero Trust Architecture (IZTA) frameworks are theoretical, with limited real-world testing in CBS environments.</td>
<td>Inadequate empirical validation of IZTA models limits their credibility and scalability in actual SaaS, IaaS, or hybrid cloud environments.</td>
<td>The present study simulated authentication scenarios in a CBS environment, implemented an IZTA model, and evaluated it using real-world threat vectors and supervised ML performance metrics.</td>
</tr>
<tr>
<td><bold>Underutilization of multi-modal trust signals</bold></td>
<td>Tiwari et al. (2021) [<xref ref-type="bibr" rid="ref-20">20</xref>]; Kancherla. (2025) [<xref ref-type="bibr" rid="ref-16">16</xref>]</td>
<td>Traditional ZTA implementations rely heavily on static or narrow trust indicators such as passwords or IP addresses.</td>
<td>Absence of integrated behavioral and contextual data (e.g., keystroke dynamics, geo-location, session metadata) undermines dynamic threat recognition.</td>
<td>The IZTA model combines keystroke biometrics with contextual trust signals, enabling dynamic authentication based on real-time user behavior and device context.</td>
</tr>
<tr>
<td><bold>Explainability of AI models</bold></td>
<td>Zhou et al. (2023) [<xref ref-type="bibr" rid="ref-17">17</xref>]</td>
<td>Most ML-based Zero Trust systems are opaque, offering no clarity on access decisions.</td>
<td>Limited explainability of ML models hinders trust, auditability, and compliance with data governance regulations in cloud environments.</td>
<td>The study used interpretable ML techniques (binary logistic regression) that generate transparent trust scores and allow administrators to trace decisions for each authentication request.</td>
</tr>
<tr>
<td><bold>Performance limitations</bold></td>
<td>Wang et al. (2023) [<xref ref-type="bibr" rid="ref-18">18</xref>]</td>
<td>Many intelligent ZTA models introduce latency and require significant computational resources, which makes real-time deployment impractical.</td>
<td>High latency and resource constraints restrict the real-time applicability of ML-driven access controls in cloud services.</td>
<td>The IZTA framework was optimized using feature engineering and lightweight ML models to enable efficient decision-making without compromising security in real-time cloud environment.</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>ZTA assumes no trust by default, requiring continuous verification of user identity, device health, location context, and access behaviors [<xref ref-type="bibr" rid="ref-1">1</xref>] and enforces principles such as least privilege access, micro-segmentation, and context-aware authorization, significantly reducing the attack surface [<xref ref-type="bibr" rid="ref-3">3</xref>]. However, the application of intelligent provisioning within ZTA frameworks, especially in cloud-based authentication, remains limited in research and practice. This study addresses this gap by proposing the Intelligent Zero Trust Architecture (IZTA) model; a framework that integrates machine learning algorithms and behavioral analytics into ZTA for dynamic authentication. The research explores how keystroke dynamics, device location, and other contextual trust signals can be used to enhance real-time access control decisions. By designing and evaluating an IZTA model specifically for Cloud-Based Services (CBS), the study contributes a novel, data-driven solution to the persistent security threats in cloud authentication systems.</p>
</sec>
<sec id="s2">
<label>2</label>
<title>Methods</title>
<p>This study employs a quasi-experimental research design to develop and evaluate an Intelligent Zero Trust Architecture (IZTA) model capable of mitigating authentication threats in Cloud-Based Services (CBS). A quasi-experimental approach is selected due to the practical limitations associated with random assignment and control of real-world cloud security environments. Unlike purely experimental designs, quasi-experiments allowed for comparative evaluation across controlled and treatment scenarios using existing datasets and systems. The evaluation of Zero Trust Architecture (ZTA) principles relevant to mitigating CBS threats and vulnerabilities was performed, and a ZTA-based integration model was formulated and tested under varying threat conditions to determine its effectiveness. The final phase involved the design, training, and implementation of the IZTA model using supervised machine learning techniques, particularly binary logistic regression.</p>
<p>To simulate the experimental process, two comparison scenarios were established:
<list list-type="simple">
<list-item><label>i.</label><p><bold>Control Scenario</bold>&#x2014;where authentication threats were analyzed under existing, non-ZTA-based security frameworks.</p></list-item>
<list-item><label>ii.</label><p><bold>Treatment Scenario</bold>&#x2014;where the same threats were analyzed under dynamic ZTA configurations based on contextual and behavioral trust indicators.</p></list-item>
</list></p>
<p>Given the nature of the research, which focuses on behavioral authentication, contextual access, and threat mitigation in cloud environments, the data collection strategy is designed to obtain large, high-quality datasets containing relevant variables such as keystroke dynamics, device telemetry, geolocation access records, and known attack vectors. The data is sourced from reputable public repositories and cybersecurity research platforms, including Kaggle Data Warehouse, National Institute of Standards and Technology&#x2019;s (NIST&#x2019;s) National Vulnerability Database (NVD), the MITRE ATT&#x0026;CK Framework, and curated datasets available through academic and industry research portals. The data collection process employed a hybrid toolset comprising Extract, Load, and Transform (ELT) pipelines, Python-based data preparation frameworks, web scraping utilities, and standardized threat databases. This comprehensive toolset ensured that the data used in the study was not only extensive and diverse but also aligned with the latest cybersecurity standards and real-world threat scenarios. The accuracy of the resulting datasets was crucial in training the machine learning models and validating the robustness of the proposed IZTA model.</p>
<p>To establish and maintain high-quality standards, this study employed a multi-pronged quality control strategy spanning data preparation, model development, evaluation, and ethical safeguards. For validity, the study employed holdout validation to ascertain predictive validity by dividing the training and test datasets into a 70:30 percentage ratio. To ascertain Machine Learning (ML) models&#x2019; validity, the cross-entropy loss function formula was applied, and to ascertain the IZTA model&#x2019;s validity, five experts in the field of Information Technology and cybersecurity were employed. Reliability is the quality of trustworthiness of the results of a study. This study ascertained ML models&#x2019; reliability through the extraction of a confusion matrix, which helped in the calculations of the Negative Predictive Value (NPV) and the Precision Rates (PR). Process reliability was attained through Python libraries, and Binary Logistic Regression algorithms.</p>
<p>The study employed a supervised machine learning algorithm, binary logistic regression under binary classification, which was selected for its transparency, interpretability, and proven performance in security prediction tasks. Binary Logistic Regression is chosen for its interpretability compared to non-linear or high-dimensional models such as neural networks, which are far more complex and require more overhead costs to implement. Further, Binary logistic regression is the most suitable algorithm for this study due to its interpretability, efficiency, and robustness in binary classification problems. Since the authentication outcome is inherently binary, grant or deny access, the model aligns naturally with logistic regression&#x2019;s predictive objective of estimating probabilities between two discrete classes. Unlike more complex black-box models (e.g., deep neural networks), logistic regression offers clear insight into how each input feature (e.g., typing rhythm, device location, session time) contributes to the final decision, which is critical for building explainable and auditable trust systems. Furthermore, logistic regression performs well with moderately sized and clean datasets, requires relatively low computational resources, and can handle collinear features through regularization techniques, making it ideal for cloud authentication use cases where real-time processing and clarity of outcomes are paramount. This balance of accuracy, transparency, and computational feasibility makes Binary Logistic Regression the preferred algorithm for developing and evaluating the proposed Intelligent Zero Trust Architecture (IZTA) model.</p>
<p>Two IZTA model prototypes were developed using different combinations of features (e.g., keystroke dynamics, location data, session attributes), and their outputs were compared for consistency in results. The confusion matrix was used as a key tool to analyze true positives, false positives, true negatives, and false negatives, thereby providing an empirical measure of the model&#x2019;s reliability across test cases. Furthermore, quality control extended to data preprocessing, where Python libraries such as Pandas were used for dataset cleansing and normalization to eliminate noise, redundancies, and inconsistencies that could bias the machine learning outcomes. Data visualization tools, including Matplotlib, were utilized to inspect and confirm the presence of logical patterns and trends before model training commenced. The emphasis on both technical accuracy and conceptual integrity ensured that the IZTA model developed through this study is both scientifically valid and practically deployable in real-world cloud security contexts.</p>
<p>All datasets were anonymized, de-identified, and processed in line with data protection guidelines. No attempt was made to reverse-engineer personal identities, and all analytic procedures focused solely on behavioral patterns, device metadata, and security event logs in abstracted formats. Furthermore, all digital tools, software libraries (e.g., Pandas, Matplotlib), and databases (e.g., Kaggle, NIST Threat Mitre Framework) were used under their respective open-source or academic research licenses. This study upheld ethical rigor across all phases from conceptualization and data acquisition to analysis and reporting, ensuring that its outputs are ethically sound, legally compliant, and academically trustworthy.</p>
<p>The initial phase of IZTA model development involves identifying and acquiring datasets that provide reliable indicators for behavioral and contextual authentication. Specifically, this study focuses on datasets related to keystroke dynamics and device location two critical attributes in determining user and device trust levels within a Zero Trust Architecture framework. Both datasets were sourced from the publicly accessible Kaggle data repository. <xref ref-type="table" rid="table-2">Table 2</xref> provides a metadata summary of the selected datasets.</p>
<table-wrap id="table-2">
<label>Table 2</label>
<caption>
<title>Datasets for IZTA model development (accessed on 26 August 2025)</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
</colgroup>
<thead>
<tr>
<th align="center">No.</th>
<th align="center">Dataset name</th>
<th align="center">Dataset location</th>
<th align="center">Dataset size</th>
</tr>
</thead>
<tbody>
<tr>
<td>1.</td>
<td>Location Intelligence Cybersecurity 2025</td>
<td><ext-link ext-link-type="uri" xlink:href="https://www.kaggle.com/datasets/wisam1985/location-intelligence-for-cybersecurity-2025">https://www.kaggle.com/datasets/wisam1985/location-intelligence-for-cybersecurity-2025</ext-link></td>
<td>65,450 Records</td>
</tr>
<tr>
<td>2.</td>
<td>DSL-StrongPasswordData</td>
<td><ext-link ext-link-type="uri" xlink:href="https://www.kaggle.com/datasets/carnegiecylab/keystroke-dynamics-benchmark-data-set">https://www.kaggle.com/datasets/carnegiecylab/keystroke-dynamics-benchmark-data-set</ext-link></td>
<td>20,400 Records</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>The training algorithm begins by loading the preprocessed device location dataset, followed by the separation of features (latitude and longitude) and labels (trust classifications). These features are then normalized and divided into training and test sets, maintaining a 70:30 ratio as previously established. The fit function of the binary logistic regression model is invoked to initiate the training process, during which the model iteratively learns optimal weights for the features using gradient descent and minimizes the loss function. The model learns to differentiate trusted from untrusted login attempts based on proximity to known threat hotspots. After training, the predict function is employed to evaluate the model&#x2019;s performance on the test dataset, with results further validated using accuracy, precision, recall, and the confusion matrix. By training the model on location-based contextual features, the IZTA framework is empowered to make informed trust decisions grounded in both spatial intelligence and behavioral insights. This enhances its alignment with Zero Trust principles, where every access request must be continuously verified before being granted.</p>
<p><bold><italic>Ethical Considerations and Data Privacy</italic></bold></p>
<p>Ethical compliance is a fundamental pillar of any credible research study, and this study adhered to established ethical standards throughout its lifecycle. The study primarily utilized non-human, secondary data sources such as publicly available datasets on keystroke dynamics, device locations, authentication events, and threat intelligence, which minimized the risk of ethical breaches involving human participants.</p>
<p>Although the data used did not involve direct human subjects, stringent measures were implemented to ensure the privacy, confidentiality, and integrity of the information analyzed. All datasets were anonymized, de-identified, and processed in line with data protection guidelines. No attempt was made to reverse-engineer personal identities, and all analytic procedures focused solely on behavioral patterns, device metadata, and security event logs in abstracted formats.</p>
<p>Furthermore, all digital tools, software libraries (e.g., Pandas, Matplotlib), and databases (e.g., Kaggle, NIST Threat Mitre Framework) were used under their respective open-source or academic research licenses. Proper attribution and citation of external works and data sources were maintained throughout the documentation and writing of this thesis.</p>
<p>In keeping with academic integrity, the contributions of other authors, datasets, and prior research were fully acknowledged. No part of the work involved plagiarism or data falsification, and care was taken to preserve transparency in the research design, implementation, and reporting process. This study upheld ethical rigor across all phases from conceptualization and data acquisition to analysis and reporting, ensuring that its outputs are ethically sound, legally compliant, and academically trustworthy.</p>
</sec>
<sec id="s3">
<label>3</label>
<title>Results</title>
<p>To evaluate the performance of the Intelligent Zero Trust Architecture (IZTA) models, the study employed two machine learning classifiers developed using binary logistic regression: one trained on the <bold>Keystroke Dynamics</bold> dataset and the other on the <bold>Device Location</bold> dataset. Both models were designed to classify authentication attempts as legitimate or malicious, based on behavioral and contextual trust indicators, respectively.</p>
<p>As shown in <xref ref-type="fig" rid="fig-1">Fig. 1</xref>, training algorithms incorporate <bold>cross-entropy loss functions</bold> as part of their learning processes. These functions serve as core validity indicators, enabling the models to minimize error through iterative optimization and to compute reliable weight and bias parameters that improve predictive accuracy.</p>
<fig id="fig-1">
<label>Figure 1</label>
<caption>
<title>Training algorithms for device location</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="JCS_70952-fig-1.tif"/>
</fig>
<p>Model validity is assessed through the accuracy score&#x2014;the proportion of correct predictions out of total predictions&#x2014;while reliability is evaluated using a confusion matrix, which measures true positives (TP), false positives (FP), true negatives (TN), and false negatives (FN).</p>
<sec id="s3_1">
<label>3.1</label>
<title>Keystroke Dynamics Model Evaluation</title>
<p>The binary logistic regression model trained on the keystroke dynamics dataset demonstrated an accuracy score of 0.8766, as shown in <xref ref-type="fig" rid="fig-2">Fig. 2</xref>.</p>
<fig id="fig-2">
<label>Figure 2</label>
<caption>
<title>Keystroke dynamics model performance evaluation (loss function)</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="JCS_70952-fig-2.tif"/>
</fig>
<p>The high accuracy in the loss function, as depicted by <xref ref-type="fig" rid="fig-2">Fig. 2</xref>, underscores the model&#x2019;s effectiveness in distinguishing between legitimate and suspicious typing behaviors. As a behavioral trust metric, keystroke dynamics proved to be a robust input for the IZTA authentication logic.</p>
<p>The confusion matrix for keystroke dynamics presented in <xref ref-type="fig" rid="fig-3">Fig. 3</xref> confirms this result:</p>

<p><list list-type="simple">
<list-item><label>A.</label><p>True Negatives: 5367 malicious login attempts were correctly identified.</p></list-item>
<list-item><label>B.</label><p>False Negatives: 753 login attempts were incorrectly classified.</p></list-item>
</list></p>
<fig id="fig-3">
<label>Figure 3</label>
<caption>
<title>The confusion matrix for keystroke dynamics</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="JCS_70952-fig-3.tif"/>
</fig>
<p>To validate Keystroke dynamics reliability and its role in the overall trust evaluation process within IZTA, the keystroke dynamics confusion matrix is used by the study to measure the Negative Predictive Value (NPV), which is the determinant of how reliable a negative prediction is. The formula for NPV is:
<disp-formula id="eqn-1"><label>(1)</label><mml:math id="mml-eqn-1" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd /><mml:mtd><mml:mrow><mml:mtext>NPV</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:mtext>True Negative</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>True Negative</mml:mtext></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mtext>False Negative</mml:mtext></mml:mrow></mml:mrow></mml:mfrac></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mrow><mml:mtext>therefore</mml:mtext></mml:mrow></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mrow><mml:mtext>NPV</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mfrac><mml:mn>5367</mml:mn><mml:mn>5367</mml:mn></mml:mfrac><mml:mo>+</mml:mo><mml:mn>753</mml:mn></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mrow><mml:mtext mathvariant="bold">NPV = 0.876956</mml:mtext></mml:mrow></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula></p>
<p><bold><xref ref-type="disp-formula" rid="eqn-1">Eq. (1)</xref>:</bold> Negative Predictive Value for Keystroke Dynamics</p>
<p><xref ref-type="disp-formula" rid="eqn-1">Eq. (1)</xref> indicates the ability of the keystroke dynamics algorithms to reliably predict a threat actor&#x2019;s keystroke dynamics at 87.696% during the authentication process.</p>
</sec>
<sec id="s3_2">
<label>3.2</label>
<title>Device Location Model Evaluation</title>
<p>The second binary logistic regression model, developed using device location data, yielded an accuracy score of 0.7357, as depicted in <xref ref-type="fig" rid="fig-4">Fig. 4</xref>.</p>
<fig id="fig-4">
<label>Figure 4</label>
<caption>
<title>Device location model performance evaluation (loss function)</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="JCS_70952-fig-4.tif"/>
</fig>
<p>Although <xref ref-type="fig" rid="fig-4">Fig. 4</xref> depicts accuracy scores that are lower than those of the keystroke dynamics model, this result still demonstrates strong predictive ability, particularly in identifying threat actors based on proximity to known attack hotspots. The model leveraged geospatial intelligence to assess risk context, enhancing the granularity of trust decisions. Cross-entropy loss and convergence through gradient descent were similarly applied, and reliability was also validated using a confusion matrix (see <xref ref-type="fig" rid="fig-5">Fig. 5</xref>).</p>
<fig id="fig-5">
<label>Figure 5</label>
<caption>
<title>The confusion matrix for device location</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="JCS_70952-fig-5.tif"/>
</fig>
<p>The confusion matrix for Device Location presented in <xref ref-type="fig" rid="fig-5">Fig. 5</xref> confirms this result:
<list list-type="simple">
<list-item><label>A.</label><p>True Positives: 14,446 Device Login Locations with CBS Authentication threats were correctly identified.</p></list-item>
<list-item><label>B.</label><p>False Positives: 5189 Device Login Locations were incorrectly classified as having CBS authentication threats.</p></list-item>
</list></p>
<p>To validate the Device Location Algorithm&#x2019;s reliability and its role in the overall trust evaluation process within IZTA, the device location confusion matrix presented in <xref ref-type="fig" rid="fig-5">Fig. 5</xref> is used by the study to measure the Precision Rate (PR), which is the determinant of how reliable a positive prediction is. <xref ref-type="disp-formula" rid="eqn-2">Eq. (2)</xref> presents the equation for PR.
<disp-formula id="eqn-2"><label>(2)</label><mml:math id="mml-eqn-2" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd /><mml:mtd><mml:mrow><mml:mi mathvariant="bold-italic">P</mml:mi><mml:mi mathvariant="bold-italic">R</mml:mi></mml:mrow><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:mrow><mml:mi mathvariant="bold-italic">T</mml:mi><mml:mi mathvariant="bold-italic">r</mml:mi><mml:mi mathvariant="bold-italic">u</mml:mi><mml:mi mathvariant="bold-italic">e</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="bold-italic">P</mml:mi><mml:mi mathvariant="bold-italic">o</mml:mi><mml:mi mathvariant="bold-italic">s</mml:mi><mml:mi mathvariant="bold-italic">i</mml:mi><mml:mi mathvariant="bold-italic">t</mml:mi><mml:mi mathvariant="bold-italic">i</mml:mi><mml:mi mathvariant="bold-italic">v</mml:mi><mml:mi mathvariant="bold-italic">e</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="bold-italic">T</mml:mi><mml:mi mathvariant="bold-italic">r</mml:mi><mml:mi mathvariant="bold-italic">u</mml:mi><mml:mi mathvariant="bold-italic">e</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="bold-italic">P</mml:mi><mml:mi mathvariant="bold-italic">o</mml:mi><mml:mi mathvariant="bold-italic">s</mml:mi><mml:mi mathvariant="bold-italic">i</mml:mi><mml:mi mathvariant="bold-italic">t</mml:mi><mml:mi mathvariant="bold-italic">i</mml:mi><mml:mi mathvariant="bold-italic">v</mml:mi><mml:mi mathvariant="bold-italic">e</mml:mi></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mi mathvariant="bold-italic">F</mml:mi><mml:mi mathvariant="bold-italic">a</mml:mi><mml:mi mathvariant="bold-italic">l</mml:mi><mml:mi mathvariant="bold-italic">s</mml:mi><mml:mi mathvariant="bold-italic">e</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="bold-italic">P</mml:mi><mml:mi mathvariant="bold-italic">o</mml:mi><mml:mi mathvariant="bold-italic">s</mml:mi><mml:mi mathvariant="bold-italic">i</mml:mi><mml:mi mathvariant="bold-italic">t</mml:mi><mml:mi mathvariant="bold-italic">i</mml:mi><mml:mi mathvariant="bold-italic">v</mml:mi><mml:mi mathvariant="bold-italic">e</mml:mi></mml:mrow></mml:mrow></mml:mfrac></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mi mathvariant="bold-italic">t</mml:mi><mml:mi mathvariant="bold-italic">h</mml:mi><mml:mi mathvariant="bold-italic">e</mml:mi><mml:mi mathvariant="bold-italic">r</mml:mi><mml:mi mathvariant="bold-italic">e</mml:mi><mml:mi mathvariant="bold-italic">f</mml:mi><mml:mi mathvariant="bold-italic">o</mml:mi><mml:mi mathvariant="bold-italic">r</mml:mi><mml:mi mathvariant="bold-italic">e</mml:mi></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mrow><mml:mi mathvariant="bold-italic">P</mml:mi><mml:mi mathvariant="bold-italic">R</mml:mi></mml:mrow><mml:mo>=</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mrow><mml:mtext mathvariant="bold">14,496</mml:mtext></mml:mrow><mml:mrow><mml:mtext mathvariant="bold">14,496 + 5189</mml:mtext></mml:mrow></mml:mfrac></mml:mstyle></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mi mathvariant="bold-italic">P</mml:mi><mml:mi mathvariant="bold-italic">R</mml:mi><mml:mo mathvariant="bold">=</mml:mo><mml:mn mathvariant="bold">0.7357</mml:mn></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula></p>
<p><bold><xref ref-type="disp-formula" rid="eqn-2">Eq. (2)</xref>:</bold> Precision Rates for Device Location</p>
<p><xref ref-type="disp-formula" rid="eqn-2">Eq. (2)</xref> indicates the ability of the Device Location algorithm to reliably predict the proximity of devices to locations with CBS authentication threats by 73.57%.</p>
</sec>
<sec id="s3_3">
<label>3.3</label>
<title>Combined Model Effectiveness and Threat Mitigation Strategy</title>
<p>To assess the mitigation potential of the IZTA models against CBS authentication threats and vulnerabilities, the study adopted a quantitative evaluation model, herein referred to as the IZTA Threat Mitigation Model.</p>
<p>Calculating the Average Effectiveness and Ineffectiveness Rates</p>
<p>In this study, Accuracy determines effectiveness. Therefore, the effectiveness rate is equated with the accuracy of the two models and is thus derived from the quantitative accuracy of the two models. To determine effectiveness and ineffectiveness rate, the calculation for the combined average accuracy of the two models. Therefore the <bold>ineffectiveness rate</bold> is the residual of the effectiveness rate. The two indicators are calculated as indicated under <xref ref-type="disp-formula" rid="eqn-3">Eq. (3)</xref>:
<disp-formula id="eqn-3"><label>(3)</label><mml:math id="mml-eqn-3" display="block"><mml:mtable columnalign="left" rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:mrow><mml:mtext mathvariant="italic">Effectiveness Rate</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mtext mathvariant="italic">Models Average Accuracy</mml:mtext></mml:mrow></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mrow><mml:mtext mathvariant="italic">Average Accuracy</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mrow><mml:mn>0.8766</mml:mn><mml:mo>+</mml:mo><mml:mn>0.7357</mml:mn></mml:mrow><mml:mn>2</mml:mn></mml:mfrac></mml:mstyle><mml:mo>=</mml:mo><mml:mn>0.8063</mml:mn></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mrow><mml:mrow><mml:mi mathvariant="normal">t</mml:mi><mml:mi mathvariant="normal">h</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mi mathvariant="normal">f</mml:mi><mml:mi mathvariant="normal">o</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mi mathvariant="normal">e</mml:mi></mml:mrow></mml:mrow><mml:mo>&#x003A;</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mrow><mml:mtext mathvariant="italic">Ineffectivenes Rate</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x2212;</mml:mo><mml:mi>A</mml:mi><mml:mi>v</mml:mi><mml:mi>e</mml:mi><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>g</mml:mi><mml:mi>e</mml:mi><mml:mi>A</mml:mi><mml:mi>c</mml:mi><mml:mi>c</mml:mi><mml:mi>u</mml:mi><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>c</mml:mi><mml:mi>y</mml:mi></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mrow><mml:mtext mathvariant="italic">Ineffectiveness Rate</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x2212;</mml:mo><mml:mn>0.8063</mml:mn><mml:mo>=</mml:mo><mml:mn>0.1937</mml:mn></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula></p>
<p><bold><xref ref-type="disp-formula" rid="eqn-3">Eq. (3)</xref>:</bold> Average Effectiveness and Ineffectiveness Rates</p>
<p>The formula and calculations in <xref ref-type="disp-formula" rid="eqn-3">Eq. (3)</xref> indicate that the IZTA models collectively mitigate approximately 80.63% of CBS authentication threats, while 19.37% may persist as residual risk even after model intervention.</p>
<sec id="s3_3_1">
<label>3.3.1</label>
<title>Threat Severity before Mitigation</title>
<p>The Initial Base Score (IBS) represents the unmitigated severity level of a given threat prior to the application of the IZTA model. IBS values were derived from simulated attack scenarios and guided by industry frameworks such as the Common Vulnerability Scoring System (CVSS). The IBS is expressed as indicated in <xref ref-type="disp-formula" rid="eqn-4">Eq. (4)</xref>:
<disp-formula id="eqn-4"><label>(4)</label><mml:math id="mml-eqn-4" display="block"><mml:mtable columnalign="left" rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:mi>I</mml:mi><mml:mi>B</mml:mi><mml:mi>S</mml:mi><mml:mo>=</mml:mo><mml:mi>f</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext mathvariant="italic">Threat Category, Likelihood, Potential Impact</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mrow><mml:mrow><mml:mi mathvariant="normal">w</mml:mi><mml:mi mathvariant="normal">h</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mi mathvariant="normal">e</mml:mi></mml:mrow></mml:mrow></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mrow><mml:mi mathvariant="bold-italic">I</mml:mi><mml:mi mathvariant="bold-italic">B</mml:mi><mml:mi mathvariant="bold-italic">S</mml:mi></mml:mrow><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:mrow><mml:mtext mathvariant="italic">denotes the Initial Base Score</mml:mtext></mml:mrow></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mi mathvariant="bold-italic">f</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mo>.</mml:mo><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mtext mathvariant="italic">captures a weighted assesment of risk parameters associated with each threat type</mml:mtext></mml:mrow></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula></p>
<p><bold><xref ref-type="disp-formula" rid="eqn-4">Eq. (4)</xref>:</bold> Initial Base Score Calculation</p>
<p>The calculation in <xref ref-type="disp-formula" rid="eqn-4">Eq. (4)</xref> offers baseline values that act as a reference point for measuring the reduction in threat impact achieved through IZTA implementation.</p>
</sec>
<sec id="s3_3_2">
<label>3.3.2</label>
<title>Threat Severity after Mitigation</title>
<p>The Mitigated Base Score (MBS) is calculated by adjusting the IBS through the application of the IZTA model&#x2019;s Ineffectiveness Rate (IR), which reflects the proportion of residual threat that bypasses the model&#x2019;s defensive mechanisms. The MBS is computed using <xref ref-type="disp-formula" rid="eqn-5">Eq. (5)</xref>:
<disp-formula id="eqn-5"><label>(5)</label><mml:math id="mml-eqn-5" display="block"><mml:mtable columnalign="left" rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:mi>M</mml:mi><mml:mi>B</mml:mi><mml:mi>S</mml:mi><mml:mo>=</mml:mo><mml:mrow><mml:mtext mathvariant="italic">Initial Base Score</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>I</mml:mi><mml:mi>B</mml:mi><mml:mi>S</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2217;</mml:mo><mml:mrow><mml:mtext mathvariant="italic">Ineffectiveness Rate</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>I</mml:mi><mml:mi>R</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mrow><mml:mrow><mml:mi mathvariant="normal">w</mml:mi><mml:mi mathvariant="normal">h</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mi mathvariant="normal">e</mml:mi></mml:mrow></mml:mrow></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mrow><mml:mi mathvariant="bold-italic">M</mml:mi><mml:mi mathvariant="bold-italic">B</mml:mi><mml:mi mathvariant="bold-italic">S</mml:mi></mml:mrow><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:mrow><mml:mtext>refers to the mitigated Base Score after IZTA intervention</mml:mtext></mml:mrow></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mrow><mml:mi mathvariant="bold-italic">I</mml:mi><mml:mi mathvariant="bold-italic">R</mml:mi></mml:mrow><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:mrow><mml:mtext>is the Ineffectiveness Rate of the IZTA model</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mn>0</mml:mn><mml:mo>&#x2264;</mml:mo><mml:mi>I</mml:mi><mml:mi>R</mml:mi><mml:mo>&#x2264;</mml:mo><mml:mn>1</mml:mn><mml:mo>)</mml:mo></mml:mrow></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mrow><mml:mtext>For example</mml:mtext></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mtext>a</mml:mtext></mml:mrow><mml:mtext>&#x00A0;</mml:mtext><mml:mrow><mml:mtext>Brute Force attack with an IBS of&#xA0;</mml:mtext></mml:mrow><mml:mn>7.00</mml:mn><mml:mtext>&#x00A0;</mml:mtext><mml:mrow><mml:mtext>and an IR of&#xA0;</mml:mtext></mml:mrow><mml:mn>0.1937</mml:mn><mml:mrow><mml:mtext>&#xA0;yields</mml:mtext></mml:mrow><mml:mo>&#x003A;</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mrow><mml:mi mathvariant="bold-italic">M</mml:mi><mml:mi mathvariant="bold-italic">B</mml:mi><mml:mi mathvariant="bold-italic">S</mml:mi></mml:mrow><mml:mo>=</mml:mo><mml:mn>7.00</mml:mn><mml:mo>&#x2217;</mml:mo><mml:mn>0.1937</mml:mn><mml:mo>=</mml:mo><mml:mn>1.36</mml:mn></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula></p>
<p><bold><xref ref-type="disp-formula" rid="eqn-5">Eq. (5)</xref>:</bold> Mitigated Base Score Calculation</p>
<p>The calculations in <xref ref-type="disp-formula" rid="eqn-5">Eq. (5)</xref> illustrate the reduction in severity facilitated by the IZTA controls, confirming the model&#x2019;s capacity to substantially lower threat impact under operational conditions.</p>
</sec>
<sec id="s3_3_3">
<label>3.3.3</label>
<title>Severity Classification Thresholds</title>
<p>To standardize the interpretation of both IBS and MBS values, the following severity rating thresholds were employed:
<list list-type="simple">
<list-item><label>i.</label><p>Low severity: 0.00&#x2013;3.99</p></list-item>
<list-item><label>ii.</label><p>Medium severity: 4.00&#x2013;6.99</p></list-item>
<list-item><label>iii.</label><p>High severity: 7.00&#x2013;10.00</p></list-item>
</list></p>
<p>These thresholds provide a consistent classification system for evaluating the residual risk associated with each threat vector before and after mitigation.</p>
</sec>
</sec>
<sec id="s3_4">
<label>3.4</label>
<title>Practical Implications</title>
<p>This quantitative framework enables both theoretical validation and real-world assessment of the IZTA model&#x2019;s threat mitigation capabilities. By applying consistent mathematical metrics and severity classifications, the study demonstrates how machine learning&#x2013;augmented security controls can substantially reduce authentication-related risks in cloud environments. The formulas also support dynamic recalculations in simulation environments, accommodating evolving threat landscapes and adaptive model training iterations as indicated in <xref ref-type="table" rid="table-3">Table 3</xref>.</p>
<table-wrap id="table-3">
<label>Table 3</label>
<caption>
<title>IZTA threat mitigation model results</title>
</caption>
<table>
<colgroup>
<col/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
</colgroup>
<thead>
<tr>
<th>No.</th>
<th align="center">Threat category</th>
<th align="center">Initial base score (IBS)</th>
<th align="center">IZTA ineffectiveness rate (IR)</th>
<th align="center">Mitigated base score (MBS)</th>
<th align="center">Severity rating</th>
</tr>
</thead>
<tbody>
<tr>
<td>1</td>
<td>Brute force attacks</td>
<td>7.00</td>
<td>0.1937</td>
<td>1.36</td>
<td>Low</td>
</tr>
<tr>
<td>2</td>
<td>Denial of service attacks</td>
<td>4.30</td>
<td>0.1937</td>
<td>0.83</td>
<td>Low</td>
</tr>
<tr>
<td>3</td>
<td>Password discovery attacks</td>
<td>3.60</td>
<td>0.1937</td>
<td>0.70</td>
<td>Low</td>
</tr>
<tr>
<td>4</td>
<td>Social engineering attacks</td>
<td>3.40</td>
<td>0.1937</td>
<td>0.66</td>
<td>Low</td>
</tr>
<tr>
<td>5</td>
<td>Man-in-the-middle attacks</td>
<td>1.40</td>
<td>0.1937</td>
<td>0.27</td>
<td>Low</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>The analysis of <xref ref-type="table" rid="table-3">Table 3</xref> helps the study to produce the IZTA model as indicated in <xref ref-type="fig" rid="fig-6">Fig. 6</xref>:</p>
<fig id="fig-6">
<label>Figure 6</label>
<caption>
<title>Visual representation of the IZTA threat mitigation model</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="JCS_70952-fig-6.tif"/>
</fig>
</sec>
<sec id="s3_5">
<label>3.5</label>
<title>Scenario-Based Simulation of IZTA Performance under Varying Conditions</title>
<p>To evaluate the robustness and adaptability of the Intelligent Zero Trust Architecture (IZTA) model, this study developed five distinct scenarios that simulate different real-world conditions affecting authentication threat mitigation in Cloud-Based Services (CBS). These simulations provide insight into the dynamic behavior of the IZTA model under varying levels of effectiveness, threat severity, and adaptive intelligence. The foundational equation for determining mitigated risk is based on the relationship indicated in <xref ref-type="disp-formula" rid="eqn-6">Eq. (6)</xref>.
<disp-formula id="eqn-6"><label>(6)</label><mml:math id="mml-eqn-6" display="block"><mml:mtable columnalign="left" rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:mrow><mml:mtext mathvariant="italic">Mitigated Base Score</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>M</mml:mi><mml:mi>B</mml:mi><mml:mi>S</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mtext mathvariant="italic">Initial Base Score</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>I</mml:mi><mml:mi>B</mml:mi><mml:mi>S</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2217;</mml:mo><mml:mrow><mml:mtext mathvariant="italic">Ineffectiveness Rate</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>I</mml:mi><mml:mi>R</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mrow><mml:mrow><mml:mi mathvariant="normal">t</mml:mi><mml:mi mathvariant="normal">h</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mi mathvariant="normal">f</mml:mi><mml:mi mathvariant="normal">o</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mi mathvariant="normal">e</mml:mi></mml:mrow></mml:mrow></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mrow><mml:mi mathvariant="bold-italic">M</mml:mi><mml:mi mathvariant="bold-italic">B</mml:mi><mml:mi mathvariant="bold-italic">S</mml:mi></mml:mrow><mml:mo>=</mml:mo><mml:mi>I</mml:mi><mml:mi>B</mml:mi><mml:mi>S</mml:mi><mml:mo>&#x2217;</mml:mo><mml:mi>I</mml:mi><mml:mi>R</mml:mi></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula></p>
<p><bold><xref ref-type="disp-formula" rid="eqn-6">Eq. (6)</xref>:</bold> Foundational Equation for Determining Mitigated Risk</p>
<p><xref ref-type="disp-formula" rid="eqn-6">Eq. (6)</xref> is used by the research work to calculate different IZTA model scenarios so as to determine the effectiveness of the IZTA model in mitigating cloud-based authentication threats and vulnerabilities under different real-life scenarios.</p>
<sec id="s3_5_1">
<label>3.5.1</label>
<title>Scenario 1: Increased IZTA Ineffectiveness (IR &#x003D; 0.35)</title>
<p>This scenario models the situation where IZTA&#x2019;s performance declines, possibly due to adversarial adaptation, degraded model learning, or infrastructural constraints. The increase in the ineffectiveness rate to 0.35 results in higher mitigated scores for each threat, as shown in <xref ref-type="table" rid="table-4">Table 4</xref>.</p>
<table-wrap id="table-4">
<label>Table 4</label>
<caption>
<title>Impact of increased IZTA ineffectiveness</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Threat category</th>
<th>IBS</th>
<th>IR</th>
<th>MBS</th>
<th>Severity</th>
</tr>
</thead>
<tbody>
<tr>
<td>Brute force attacks</td>
<td>7.00</td>
<td>0.35</td>
<td>2.45</td>
<td>Medium</td>
</tr>
<tr>
<td>Denial of service attacks</td>
<td>4.30</td>
<td>0.35</td>
<td>1.51</td>
<td>Low</td>
</tr>
<tr>
<td>Password discovery attacks</td>
<td>3.60</td>
<td>0.35</td>
<td>1.26</td>
<td>Low</td>
</tr>
<tr>
<td>Social engineering attacks</td>
<td>3.40</td>
<td>0.35</td>
<td>1.19</td>
<td>Low</td>
</tr>
<tr>
<td>Man-in-the-middle attacks</td>
<td>1.40</td>
<td>0.35</td>
<td>0.49</td>
<td>Low</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>In Scenario 1 as highlighted by <xref ref-type="table" rid="table-4">Table 4</xref>, when the ineffectiveness of IZTA is increased by increasing the values of its ineffectiveness rate (IR), there is a slight elevation in threat severity is observed, with brute force attacks approaching a medium-risk threshold, highlighting the need for continuous model tuning.</p>

</sec>
<sec id="s3_5_2">
<label>3.5.2</label>
<title>Scenario 2: Enhanced IZTA Efficiency (IR &#x003D; 0.10)</title>
<p>In this simulation, the IZTA model becomes more effective through optimization of its learning algorithms and contextual feature integration. The ineffectiveness rate is reduced to 0.10, reflecting heightened model responsiveness as indicated in <xref ref-type="table" rid="table-5">Table 5</xref>.</p>
<table-wrap id="table-5">
<label>Table 5</label>
<caption>
<title>Enhanced effectiveness with reduced IR</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Threat category</th>
<th>IBS</th>
<th>IR</th>
<th>MBS</th>
<th>Severity</th>
</tr>
</thead>
<tbody>
<tr>
<td>Brute force attacks</td>
<td>7.00</td>
<td>0.10</td>
<td>0.70</td>
<td>Low</td>
</tr>
<tr>
<td>Denial of service attacks</td>
<td>4.30</td>
<td>0.10</td>
<td>0.43</td>
<td>Low</td>
</tr>
<tr>
<td>Password discovery attacks</td>
<td>3.60</td>
<td>0.10</td>
<td>0.36</td>
<td>Low</td>
</tr>
<tr>
<td>Social engineering attacks</td>
<td>3.40</td>
<td>0.10</td>
<td>0.34</td>
<td>Low</td>
</tr>
<tr>
<td>Man-in-the-middle attacks</td>
<td>1.40</td>
<td>0.10</td>
<td>0.14</td>
<td>Low</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>All threats remain well within the low severity bracket, indicating a strong performance from the IZTA model in a stabilized environment.</p>
</sec>
<sec id="s3_5_3">
<label>3.5.3</label>
<title>Scenario 3: Surge in Threat Landscape (IBS Spike)</title>
<p>This scenario assumes a spike in brute force attacks due to the discovery of a novel vulnerability or exploitation technique, raising the initial score from 7.00 to 9.00 while IR remains constant at 0.1937. This is as indicated by <xref ref-type="table" rid="table-6">Table 6</xref>.</p>
<table-wrap id="table-6">
<label>Table 6</label>
<caption>
<title>Increased IBS for brute force attack</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Threat category</th>
<th>IBS</th>
<th>IR</th>
<th>MBS</th>
<th>Severity</th>
</tr>
</thead>
<tbody>
<tr>
<td>Brute force attacks</td>
<td>9.00</td>
<td>0.1937</td>
<td>1.74</td>
<td>Low</td>
</tr>
<tr>
<td>Denial of service attacks</td>
<td>4.30</td>
<td>0.1937</td>
<td>0.83</td>
<td>Low</td>
</tr>
<tr>
<td>Password discovery attacks</td>
<td>3.60</td>
<td>0.1937</td>
<td>0.70</td>
<td>Low</td>
</tr>
<tr>
<td>Social engineering attacks</td>
<td>3.40</td>
<td>0.1937</td>
<td>0.66</td>
<td>Low</td>
</tr>
<tr>
<td>Man-in-the-middle attacks</td>
<td>1.40</td>
<td>0.1937</td>
<td>0.27</td>
<td>Low</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>Despite the escalation in initial risk score, IZTA effectively mitigates the impact to maintain a low severity profile.</p>
</sec>
<sec id="s3_5_4">
<label>3.5.4</label>
<title>Scenario 4: Selective Optimization (Variable IR by Threat Type)</title>
<p>This scenario models adaptive tuning where different IR values are applied based on the threat category, reflecting a mature IZTA model trained to recognize and prioritize specific threats.</p>
<p><xref ref-type="table" rid="table-7">Table 7</xref> indicates that customized response patterns enhance IZTA&#x2019;s risk-to-effort ratio, leading to more efficient security operations.</p>
<table-wrap id="table-7">
<label>Table 7</label>
<caption>
<title>Threat-specific IR optimization</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Threat category</th>
<th>IBS</th>
<th>IR</th>
<th>MBS</th>
<th>Severity</th>
</tr>
</thead>
<tbody>
<tr>
<td>Brute force attacks</td>
<td>7.00</td>
<td>0.12</td>
<td>0.84</td>
<td>Low</td>
</tr>
<tr>
<td>Denial of service attacks</td>
<td>4.30</td>
<td>0.18</td>
<td>0.77</td>
<td>Low</td>
</tr>
<tr>
<td>Password discovery attacks</td>
<td>3.60</td>
<td>0.15</td>
<td>0.54</td>
<td>Low</td>
</tr>
<tr>
<td>Social engineering attacks</td>
<td>3.40</td>
<td>0.20</td>
<td>0.68</td>
<td>Low</td>
</tr>
<tr>
<td>Brute force attacks</td>
<td>7.00</td>
<td>0.12</td>
<td>0.84</td>
<td>Low</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s3_5_5">
<label>3.5.5</label>
<title>Scenario 5: Learning over Time (Dynamic IR Reduction)</title>
<p>In this final scenario depicted by <xref ref-type="table" rid="table-8">Table 8</xref>, IZTA&#x2019;s machine learning modules evolve, reducing the IR across iterations. This simulates long-term deployment with continuous learning.</p>
<table-wrap id="table-8">
<label>Table 8</label>
<caption>
<title>IR declines over time (brute force as example)</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Iteration</th>
<th>IR</th>
<th>MBS (Brute Force)</th>
<th>Severity</th>
</tr>
</thead>
<tbody>
<tr>
<td>1</td>
<td>0.25</td>
<td>1.75</td>
<td>Low</td>
</tr>
<tr>
<td>2</td>
<td>0.20</td>
<td>1.40</td>
<td>Low</td>
</tr>
<tr>
<td>3</td>
<td>0.15</td>
<td>1.05</td>
<td>Low</td>
</tr>
<tr>
<td>4</td>
<td>0.10</td>
<td>0.70</td>
<td>Low</td>
</tr>
<tr>
<td>5</td>
<td>0.05</td>
<td>0.35</td>
<td>Low</td>
</tr>
</tbody>
</table>
</table-wrap>
<p><xref ref-type="table" rid="table-8">Table 8</xref> indicates that progressive model refinement leads to an exponential reduction in threat severity, confirming the scalability and learning capability of IZTA.</p>

</sec>
<sec id="s3_5_6">
<label>3.5.6</label>
<title>Summary of Scenario Simulations</title>
<p>The different scenarios depicted by <xref ref-type="table" rid="table-4">Tables 4</xref>&#x2013;<xref ref-type="table" rid="table-8">8</xref> are summarized by the study to give an overview of scenario outcomes as indicated in <xref ref-type="table" rid="table-9">Table 9</xref>.</p>
<table-wrap id="table-9">
<label>Table 9</label>
<caption>
<title>Overview of scenario outcomes</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
</colgroup>
<thead>
<tr>
<th align="center">Scenario</th>
<th align="center">Simulated condition</th>
<th align="center">Risk trend</th>
<th align="center">Key insight</th>
</tr>
</thead>
<tbody>
<tr>
<td>1. Increased IR</td>
<td>Decreased model effectiveness</td>
<td>Risk increases</td>
<td>High-risk vectors re-emerge</td>
</tr>
<tr>
<td>2. Reduced IR</td>
<td>Improved model effectiveness</td>
<td>Risk reduces</td>
<td>Model achieves significant threat control</td>
</tr>
<tr>
<td>3. Increased IBS</td>
<td>Escalating threat landscape</td>
<td>Risk controlled</td>
<td>IZTA effectively absorbs threat surges</td>
</tr>
<tr>
<td>4. Variable IR</td>
<td>Adaptive threat learning</td>
<td>Efficient mitigation</td>
<td>Threat-specific responses enhance resilience</td>
</tr>
<tr>
<td>5. Learning IR (Iterative decline)</td>
<td>Continuous model training</td>
<td>Long-term reduction</td>
<td>Sustained learning leads to proactive defense</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>These scenarios demonstrate the flexibility, scalability, and learning capacity of the IZTA model under real-world authentication threat conditions. They also underscore the importance of ongoing monitoring, adaptive learning, and contextual intelligence in modern cybersecurity frameworks.</p>
</sec>
</sec>
<sec id="s3_6">
<label>3.6</label>
<title>Modeling and Equation-Based Scenario Simulations</title>
<p>This section presents a set of mathematical scenarios simulated to evaluate the behavior of the Intelligent Zero Trust Architecture (IZTA) model under varying threat conditions and ineffectiveness rates. Each scenario applies a modified version of the base formula for calculating the Mitigated Base Score (MBS) as indicated by <xref ref-type="disp-formula" rid="eqn-7">Eq. (7)</xref>.
<disp-formula id="eqn-7"><label>(7)</label><mml:math id="mml-eqn-7" display="block"><mml:mtable columnalign="left" rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:mi>M</mml:mi><mml:mi>B</mml:mi><mml:mi>S</mml:mi><mml:mo>=</mml:mo><mml:mi>I</mml:mi><mml:mi>B</mml:mi><mml:mi>S</mml:mi><mml:mo>&#x2217;</mml:mo><mml:mi>I</mml:mi><mml:mi>R</mml:mi></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mrow><mml:mtext>where</mml:mtext></mml:mrow></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mrow><mml:mtext mathvariant="bold">MBS</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mtext>Mitigated Base Score&#xA0;</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>The residual Threat severity after IZTA intervention</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mrow><mml:mtext mathvariant="bold">IBS</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mtext>Initial Base Score&#xA0;</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>As measured by CVSS of threat baseline</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mrow><mml:mtext mathvariant="bold">IR</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mtext>IZTA Ineffectiveness Rate&#xA0;</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>The proportion of the threat not mitigated</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula></p>
<p><bold><xref ref-type="disp-formula" rid="eqn-7">Eq. (7)</xref>:</bold> Base Formula for Calculating the Mitigated Base Score.</p>
<p>As per the formula, <xref ref-type="disp-formula" rid="eqn-7">Eq. (7)</xref> scenarios simulate potential variations in the security environment and system performance.</p>
<sec id="s3_6_1">
<label>3.6.1</label>
<title>Scenario 1: Increased Ineffectiveness Rate (IR &#x003D; 0.35)</title>
<p>In this scenario, the ineffectiveness rate is raised from the baseline (IR &#x003D; 0.1937) to 0.35 to simulate model degradation due to emerging threat complexity or model drift. The new formula becomes:
<disp-formula id="ueqn-8"><mml:math id="mml-ueqn-8" display="block"><mml:mi>M</mml:mi><mml:mi>B</mml:mi><mml:mi>S</mml:mi><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>I</mml:mi><mml:mi>B</mml:mi><mml:mi>S</mml:mi><mml:mo>&#x2217;</mml:mo><mml:mn>0.35</mml:mn></mml:math></disp-formula></p>
<p>This leads to a higher residual threat score, especially for high-severity vectors such as brute force attacks. For example:
<disp-formula id="ueqn-9"><mml:math id="mml-ueqn-9" display="block"><mml:mi>M</mml:mi><mml:mi>B</mml:mi><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>B</mml:mi><mml:mi>r</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi><mml:mi>e</mml:mi><mml:mi>F</mml:mi><mml:mi>o</mml:mi><mml:mi>r</mml:mi><mml:mi>c</mml:mi><mml:mi>e</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mn>7.00</mml:mn><mml:mo>&#x2217;</mml:mo><mml:mn>0.35</mml:mn><mml:mo>=</mml:mo><mml:mn>2.45</mml:mn></mml:math></disp-formula></p>
<p>Although still within the &#x201C;Low&#x201D; severity classification, such values approach the threshold of medium risk, indicating the need for model retraining or layered mitigation.</p>
</sec>
<sec id="s3_6_2">
<label>3.6.2</label>
<title>Scenario 2: Decreased Ineffectiveness Rate (IR &#x003D; 0.10)</title>
<p>This scenario reflects enhanced IZTA effectiveness due to improved learning or optimization. The ineffectiveness rate is reduced to 0.10, resulting in the formula:
<disp-formula id="ueqn-10"><mml:math id="mml-ueqn-10" display="block"><mml:mi>M</mml:mi><mml:mi>B</mml:mi><mml:mi>S</mml:mi><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>I</mml:mi><mml:mi>B</mml:mi><mml:mi>S</mml:mi><mml:mo>&#x2217;</mml:mo><mml:mn>0.10</mml:mn></mml:math></disp-formula></p>
<p>For instance:
<disp-formula id="ueqn-11"><mml:math id="mml-ueqn-11" display="block"><mml:mi>M</mml:mi><mml:mi>B</mml:mi><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>D</mml:mi><mml:mi>o</mml:mi><mml:mi>S</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mn>4.30</mml:mn><mml:mo>&#x2217;</mml:mo><mml:mn>0.10</mml:mn><mml:mo>=</mml:mo><mml:mn>0.43</mml:mn></mml:math></disp-formula></p>
<p>This outcome indicates a significantly improved security posture, with all threats remaining well within low severity ranges, validating the IZTA&#x2019;s optimization benefits.</p>
</sec>
<sec id="s3_6_3">
<label>3.6.3</label>
<title>Scenario 3: Elevated Threat Landscape (IBS Surge)</title>
<p>This scenario assumes a spike in the initial threat score for Brute Force attacks due to a newly discovered exploit, increasing IBS from 7.0 to 9.0. Maintaining the original ineffectiveness rate of 0.1937, the formula becomes:
<disp-formula id="ueqn-12"><mml:math id="mml-ueqn-12" display="block"><mml:mi>M</mml:mi><mml:mi>B</mml:mi><mml:mi>S</mml:mi><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mn>3</mml:mn></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mn>9.00</mml:mn><mml:mo>&#x2217;</mml:mo><mml:mn>0.1937</mml:mn><mml:mo>=</mml:mo><mml:mn>1.7433</mml:mn></mml:math></disp-formula></p>
<p>Despite the rise in IBS, the resulting MBS still falls under low severity, demonstrating IZTA&#x2019;s resilience to moderate threat escalation.</p>
</sec>
<sec id="s3_6_4">
<label>3.6.4</label>
<title>Scenario 4: Selective Optimization per Threat Category (Adaptive IR)</title>
<p>In this scenario, the ineffectiveness rate is varied by threat type to simulate targeted model tuning. The adjusted formulas are as follows:
<list list-type="simple">
<list-item><label>i.</label><p>Brute Force Attacks: MBS<sub>BF</sub> &#x003D; IBS &#x00D7; 0.12</p></list-item>
<list-item><label>ii.</label><p>Denial of Service: MBS<sub>DoS</sub> &#x003D; IBS &#x00D7; 0.18</p></list-item>
<list-item><label>iii.</label><p>Password Discovery: MBS<sub>Pwd</sub> &#x003D; IBS &#x00D7; 0.15</p></list-item>
<list-item><label>iv.</label><p>Social Engineering: MBS<sub>SE</sub> &#x003D; IBS &#x00D7; 0.20</p></list-item>
<list-item><label>v.</label><p>Man-in-the-Middle: MBS<sub>MitM</sub> &#x003D; IBS &#x00D7; 0.25</p></list-item>
</list></p>
<p>This adaptive approach demonstrates the potential of fine-grained ML tuning for different threat vectors, yielding cost-effective mitigation with minimal residual risk.</p>
</sec>
<sec id="s3_6_5">
<label>3.6.5</label>
<title>Scenario 5: Learning over Time (Dynamic IR Reduction)</title>
<p>This scenario models an iterative reduction in the ineffectiveness rate to reflect continuous learning and model enhancement over time. The ineffectiveness rate reduces linearly by 0.05 per iteration. The evolving formula is:
<list list-type="simple">
<list-item><label>i.</label><p>Iteration 1: MB<sub>S1</sub> &#x003D; IBS &#x00D7; 0.25</p></list-item>
<list-item><label>ii.</label><p>Iteration 2: MB<sub>S2</sub> &#x003D; IBS &#x00D7; 0.20</p></list-item>
<list-item><label>iii.</label><p>Iteration 3: MB<sub>S3</sub> &#x003D; IBS &#x00D7; 0.15</p></list-item>
<list-item><label>iv.</label><p>Iteration 4: MB<sub>S4</sub> &#x003D; IBS &#x00D7; 0.10</p></list-item>
<list-item><label>v.</label><p>Iteration 5: MB<sub>S5</sub> &#x003D; IBS &#x00D7; 0.05</p></list-item>
</list></p>
<p>This scenario illustrates how the IZTA model becomes increasingly effective over time, leading to near-zero residual threat exposure, aligning with the theoretical objectives of machine learning-based ZTA.</p>
</sec>
</sec>
</sec>
<sec id="s4">
<label>4</label>
<title>Discussion</title>
<p>The IZTA model in <xref ref-type="fig" rid="fig-6">Fig. 6</xref> indicates that the analysis of mitigated base scores (MBS) across various authentication-related threat categories provides critical insights into the practical performance of the Intelligent Zero Trust Architecture (IZTA) model. The results demonstrate that all computed MBS values fall within the &#x201C;Low&#x201D; severity classification (0.00&#x2013;3.99) as defined by the study&#x2019;s standardized risk threshold. This uniformity across different threat vectors indicates a high level of consistency in the IZTA model&#x2019;s performance. Regardless of the initial threat magnitude, the mitigation process successfully suppresses the residual risk to manageable levels. This confirms the IZTA model&#x2019;s reliability and resilience under varied attack conditions. A particularly significant outcome is the model&#x2019;s ability to neutralize high-risk threats. For instance, Brute Force Attacks, which had an Initial Base Score (IBS) of 7.00&#x2014;qualifying as a &#x201C;High&#x201D; severity risk&#x2014;were mitigated down to an MBS of 1.36. This represents an approximate 80.5% reduction in threat intensity. Similar suppression was observed for other attack categories such as Credential Stuffing, Password Discovery Attacks, and Phishing-related intrusions. These findings underscore the IZTA model&#x2019;s potential to significantly reduce the threat surface in real-world cloud authentication environments.</p>

<p>The successful performance of the IZTA model is further attributed to its hybrid approach, integrating both behavioral and contextual trust signals. Behavioral analytics, such as keystroke dynamics, capture user interaction patterns, while contextual indicators like device location provide environmental validation. This dual-faceted trust evaluation supports the Zero Trust Architecture (ZTA) principles of continuous authentication, least privilege access, and adaptive policy enforcement. The ability of the model to dynamically interpret user legitimacy based on multiple trust layers contributes to its overall precision and effectiveness.</p>
<p>The consistent threat suppression achieved through this model has practical implications for cloud service providers, cybersecurity architects, and policy makers. The IZTA model not only strengthens identity verification mechanisms in real time but also contributes toward compliance with cybersecurity frameworks such as NIST&#x2019;s ZTA model. Moreover, its modular design and explainable machine learning foundation make it adaptable for deployment in high-risk sectors such as finance, healthcare, education, and public administration.</p>
<p>The quantitative application and evaluation of the Intelligent Zero Trust Architecture (IZTA) Threat Mitigation Model yielded critical findings that affirm the model&#x2019;s effectiveness in enhancing authentication security for Cloud-Based Services (CBS). The key results are discussed below, along with their broader implications for cybersecurity theory, practice, and policy. One of the most significant outcomes of the study is the observed uniformity in threat reduction across all evaluated attack categories. Following mitigation via the IZTA model, all threat vectors, including Brute Force, Denial of Service, Password Discovery, Social Engineering, and Man-in-the-Middle attacks, resulted in Mitigated Base Scores (MBS) that fell within the &#x201C;Low&#x201D; severity range. This cross-category consistency suggests a high level of generalizability and scalability of the IZTA model, reinforcing its applicability across diverse authentication environments in the cloud.</p>
<p>The model&#x2019;s capacity to suppress high-severity threats to low-impact levels further validates its robustness. For instance, Brute Force Attacks, which initially scored an IBS of 7.00 (classified as &#x201C;High&#x201D;), were mitigated to an MBS of 1.36 (classified as &#x201C;Low&#x201D;). This represents a substantial threat reduction of over 80%. Similar threat suppression was observed across other categories, including credential-based and session-layer attacks. These outcomes demonstrate that the IZTA model effectively transforms potentially catastrophic threats into manageable security events. A foundational strength of the IZTA model lies in its trust evaluation mechanism, which synergistically integrates both behavioral and contextual signals. Behavioral attributes such as keystroke dynamics provide continuous insight into user interaction patterns, while contextual factors like device location and access timing add an additional layer of dynamic verification. This dual-modality trust scoring aligns with Zero Trust principles of continuous verification, minimal privilege, and adaptive access control. Consequently, the model ensures that access decisions are evidence-based, context-aware, and responsive to evolving threat conditions.</p>
<p>From a practical perspective, the findings affirm that organizations can achieve higher levels of authentication assurance without imposing excessive system complexity or latency. For cybersecurity practitioners, the study provides a replicable model that integrates explainable machine learning with Zero Trust protocols. Theoretically, the study contributes to the evolving discourse on trust modeling in access control systems by demonstrating how multi-modal data streams can enhance security decision-making.</p>
</sec>
<sec id="s5">
<label>5</label>
<title>Conclusion</title>
<p>This paper presents the development, application, and evaluation of the Intelligent Zero Trust Architecture (IZTA) model designed to mitigate authentication threats in Cloud-Based Services (CBS). It outlines the model construction process, which integrates behavioral and contextual trust signals, specifically keystroke dynamics and device location, within a machine learning-driven access control framework. A six-step model development approach is adopted, beginning with threat identification and classification, and the application of an ineffectiveness rate (IR). Equations are formulated to demonstrate pre- and post-mitigation threat scores, and visualizations are used to present comparative severity ratings across threat vectors. The quantitative implementation showed that the IZTA model consistently reduced threat severity across all evaluated categories, transforming high-risk threats (e.g., brute force attacks) into low-severity risks. Findings from this study demonstrate the synergistic value of combining behavioral and contextual authentication signals. By leveraging interpretable machine learning (specifically binary logistic regression), the IZTA model ensured transparent decision-making while aligning with Zero Trust principles such as continuous validation and policy enforcement.</p>
<p>The study recommends that moving forward, organizations begin with interpretable models such as logistic regression for initial behavioral modeling, given their ease of implementation and transparency. Over time, however, more advanced and adaptive methods should be introduced to improve threat mitigation accuracy and reduce ineffectiveness rates. These may include the use of ensemble machine learning models like Random Forests and Support Vector Machines, as well as advanced strategies such as trust signal fusion, risk-adaptive scoring, and behavior-based anomaly detection. Incorporating these enhancements will improve model precision, reduce false positives, and enable real-time, intelligent decision-making in authentication workflows within CBS environments. These recommendations advocate for a proactive, data-driven, and layered security strategy centered on Zero Trust principles. They emphasize the need for both technical precision and adaptive policy mechanisms to ensure resilient, scalable, and intelligent authentication systems capable of withstanding evolving threat landscapes in cloud-based infrastructures.</p>
<p>For future research, organizations should experiment with more sophisticated machine learning architectures such as Support Vector Machines (SVMs), Random Forests, and Deep Learning models for enhanced performance and scalability. Furthermore, the use of federated learning approaches can enable distributed training of IZTA models across multiple cloud nodes without compromising user data privacy&#x2014;a critical consideration in modern security practices. Incorporating trust signal fusion techniques, adaptive risk thresholds, and confidence-based decision mechanisms may also reduce false positives and improve the model&#x2019;s reliability in production settings. Future work should also prioritize real-world pilot implementations of IZTA models within operational cloud environments to observe system behavior under live traffic and potential attack conditions. This would allow researchers to refine the models based on actual user interaction patterns and attack vectors encountered in practice. These future research directions emphasize the need for continued innovation in intelligent cybersecurity design. By integrating automation, signal diversity, adaptive learning, and real-world deployment, future studies can build upon the foundation established in this thesis and contribute to the development of resilient, intelligent authentication systems for the next generation of cloud computing environments.</p>
</sec>
</body>
<back>
<ack>
<p>We wish to acknowledge the Department of Information Technology, Kibabii University, for allowing us to carry out this study.</p>
</ack>
<sec>
<title>Funding Statement</title>
<p>The authors received no specific funding for this study.</p>
</sec>
<sec>
<title>Author Contributions</title>
<p>The authors confirm contribution to this paper as follows: Study Conceptualization, Victor Otieno Mony, Anselemo Peters Ikoha, Roselida O. Maroko, Model Development, Victor Otieno Mony, Model Equations, Victor Otieno Mony, Roselida O. Maroko, Results Analysis, Victor Otieno Mony, Results Discussion &#x0026; Presentation, Victor Otieno Mony, Anselemo Peters Ikoha, Roselida O. Maroko. All authors reviewed the results and approved the final version of the manuscript.</p>
</sec>
<sec sec-type="data-availability">
<title>Availability of Data and Materials</title>
<p>The authors confirm that the data supporting the findings of this study are available within the article. Further, the datasets used in this study are available online. The Device Location dataset is available at: <ext-link ext-link-type="uri" xlink:href="https://www.kaggle.com/datasets/wisam1985/location-intelligence-for-cybersecurity-2025">https://www.kaggle.com/datasets/wisam1985/location-intelligence-for-cybersecurity-2025</ext-link>, while the Device Location Datasets are available at: <ext-link ext-link-type="uri" xlink:href="https://www.kaggle.com/datasets/carnegiecylab/keystroke-dynamics-benchmark-data-set">https://www.kaggle.com/datasets/carnegiecylab/keystroke-dynamics-benchmark-data-set</ext-link> (accessed on 26 August 2025).</p>
</sec>
<sec>
<title>Ethics Approval</title>
<p>Not applicable.</p>
</sec>
<sec sec-type="COI-statement">
<title>Conflicts of Interest</title>
<p>The authors declare no conflicts of interest to report regarding the present study.</p>
</sec>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Mattsson</surname> <given-names>U</given-names></string-name></person-group>. <chapter-title>Zero trust architecture</chapter-title>. In: <person-group person-group-type="editor"><string-name><surname>Mattsson</surname> <given-names>U</given-names></string-name></person-group>, editor. <source>Controlling privacy and the use of data assets-volume 1</source>. <publisher-loc>Abingdon, UK</publisher-loc>: <publisher-name>Talylor Francis Group</publisher-name>; <year>2022</year>. p. <fpage>127</fpage>&#x2013;<lpage>34</lpage>.</mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Phiayura</surname> <given-names>P</given-names></string-name>, <string-name><surname>Teerakanok</surname> <given-names>S</given-names></string-name></person-group>. <article-title>A comprehensive framework for migrating to zero trust architecture</article-title>. <source>IEEE Access</source>. <year>2023</year>;<volume>11</volume>(<issue>6</issue>):<fpage>19487</fpage>&#x2013;<lpage>511</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2023.3248622</pub-id>.</mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><collab>Kirti</collab></person-group>. <article-title>Exploring cloud security challenges: an in-depth analysis of emerging threats and mitigation strategies</article-title>. In: <conf-name>2025 3rd International Conference on Disruptive Technologies (ICDT); 2025 Mar 7&#x2013;8; Greater Noida, India</conf-name>. doi:<pub-id pub-id-type="doi">10.1109/ICDT63985.2025.10986561</pub-id>.</mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Joshi</surname> <given-names>M</given-names></string-name>, <string-name><surname>Budhani</surname> <given-names>S</given-names></string-name>, <string-name><surname>Tewari</surname> <given-names>N</given-names></string-name>, <string-name><surname>Prakash</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Analytical review of data security in cloud computing</article-title>. In: <conf-name> 2021 2nd International Conference on Intelligent Engineering and Management (ICIEM); 2021 Apr 28&#x2013;30; London, UK</conf-name>. doi:<pub-id pub-id-type="doi">10.1109/iciem51511.2021.9445355</pub-id>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Alotaibi</surname> <given-names>AF</given-names></string-name>, <string-name><surname>Alzain</surname> <given-names>MA</given-names></string-name>, <string-name><surname>Masud</surname> <given-names>M</given-names></string-name>, <string-name><surname>Jhanjhi</surname> <given-names>NZ</given-names></string-name></person-group>. <article-title>A comprehensive survey on security threats and countermeasures of cloud computing environment</article-title>. <source>Turk J Comput Math Educ</source>. <year>2021</year>;<volume>12</volume>(<issue>9</issue>):<fpage>1978</fpage>&#x2013;<lpage>90</lpage>.</mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Abdullahi</surname> <given-names>AD</given-names></string-name>, <string-name><surname>Dargahi</surname> <given-names>T</given-names></string-name>, <string-name><surname>Hammoudeh</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Poster: continuous authentication in highly connected 6G-enabled transportation systems</article-title>. In: <conf-name>2023 IEEE Vehicular Networking Conference (VNC); 2023 Apr 26&#x2013;28; Istanbul, T&#x00FC;rkiye</conf-name>. doi:<pub-id pub-id-type="doi">10.1109/VNC57357.2023.10136342</pub-id>.</mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Gollmann</surname> <given-names>D</given-names></string-name></person-group>. <source>Authentication, Authorisation &#x0026; Accountability (AAA) knowledge area issue</source>. <publisher-loc>Bristol, UK</publisher-loc>: <publisher-name>The Cyber Security Body of Knowledge</publisher-name>; <year>2019</year>.</mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Krishnamoorthy</surname> <given-names>R</given-names></string-name>, <string-name><surname>Arun</surname> <given-names>S</given-names></string-name>, <string-name><surname>Sujitha</surname> <given-names>N</given-names></string-name>, <string-name><surname>Vijayalakshmi</surname> <given-names>KM</given-names></string-name>, <string-name><surname>Karthiga</surname> <given-names>S</given-names></string-name>, <string-name><surname>Thiagarajan</surname> <given-names>R</given-names></string-name></person-group>. <article-title>Proposal of HMAC based protocol for message authenication in kerberos authentication protocol</article-title>. In: <conf-name>2022 Second International Conference on Artificial Intelligence and Smart Energy (ICAIS); 2022 Feb 23&#x2013;25; Coimbatore, India</conf-name>. doi:<pub-id pub-id-type="doi">10.1109/ICAIS53314.2022.9742992</pub-id>.</mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Priyadharshini</surname> <given-names>S</given-names></string-name>, <string-name><surname>Rajmohan</surname> <given-names>R</given-names></string-name></person-group>. <article-title>Analysis on database security model against NOSQL injection</article-title>. <source>Int J Sci Res Comput Sci Eng Inf Technol</source>. <year>2017</year>;<volume>2</volume>(<issue>2</issue>):<fpage>2456</fpage>&#x2013;<lpage>3307</lpage>.</mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Dostalek</surname> <given-names>L</given-names></string-name>, <string-name><surname>Safarik</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Strong password authentication with AKA authentication mechanism</article-title>. In: <conf-name>2017 International Conference on Applied Electronics (AE); 2017 Sep 5&#x2013;6; Pilsen, Czech Republic</conf-name>.</mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Akram</surname> <given-names>SV</given-names></string-name>, <string-name><surname>Joshi</surname> <given-names>SK</given-names></string-name>, <string-name><surname>Deorari</surname> <given-names>R</given-names></string-name></person-group>. <article-title>Web application based authentication system</article-title>. In: <conf-name>2022 International Interdisciplinary Humanitarian Conference for Sustainability (IIHC); 2022 Nov 18&#x2013;19; Bengaluru, India</conf-name>. doi:<pub-id pub-id-type="doi">10.1109/IIHC55949.2022.10059984</pub-id>.</mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Raheman</surname> <given-names>F</given-names></string-name>, <string-name><surname>Bhagat</surname> <given-names>T</given-names></string-name>, <string-name><surname>Vermeulen</surname> <given-names>B</given-names></string-name>, <string-name><surname>Van Daele</surname> <given-names>P</given-names></string-name></person-group>. <article-title>Will zero vulnerability computing (ZVC) ever be possible? Testing the hypothesis</article-title>. <source>Future Internet</source>. <year>2022</year>;<volume>14</volume>(<issue>8</issue>):<fpage>238</fpage>. doi:<pub-id pub-id-type="doi">10.3390/fi14080238</pub-id>.</mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Abdulsalam</surname> <given-names>YS</given-names></string-name>, <string-name><surname>Hedabou</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Security and privacy in cloud computing: technical review</article-title>. <source>Future Internet</source>. <year>2022</year>;<volume>14</volume>(<issue>1</issue>):<fpage>11</fpage>. doi:<pub-id pub-id-type="doi">10.3390/fi14010011</pub-id>.</mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ahmadi</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Zero trust architecture in cloud networks: application, challenges and future opportunities</article-title>. <source>J Eng Res Rep</source>. <year>2024</year>;<volume>26</volume>(<issue>2</issue>):<fpage>215</fpage>&#x2013;<lpage>28</lpage>. doi:<pub-id pub-id-type="doi">10.9734/jerr/2024/v26i21083</pub-id>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Alawneh</surname> <given-names>M</given-names></string-name>, <string-name><surname>Abbadi</surname> <given-names>IM</given-names></string-name></person-group>. <article-title>Integrating trusted computing mechanisms with trust models to achieve zero trust principles</article-title>. In: <conf-name>2022 9th International Conference on Internet of Things: Systems, Management and Security (IOTSMS); 2022 Nov 29&#x2013;Dec 1; Milan, Italy</conf-name>. doi:<pub-id pub-id-type="doi">10.1109/iotsms58070.2022.10062269</pub-id>.</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kancherla</surname> <given-names>VM</given-names></string-name></person-group>. <article-title>The next-generation cloud security model: AI-powered zero trust and adaptive threat prevention</article-title>. <source>Int J Emerg Trends Comput Sci Inf Technol</source>. <year>2025</year>;<volume>6</volume>:<fpage>82</fpage>&#x2013;<lpage>90</lpage>. doi:<pub-id pub-id-type="doi">10.63282/3050-9246.ijetcsit-v6i1p110</pub-id>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Zhou</surname> <given-names>L</given-names></string-name>, <string-name><surname>Song</surname> <given-names>X</given-names></string-name>, <string-name><surname>Yao</surname> <given-names>G</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>H</given-names></string-name>, <string-name><surname>Li</surname> <given-names>J</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>S</given-names></string-name>, <etal>et al.</etal></person-group> <article-title>Intelligent sensing terminal distributed computing architecture of IoT for EMS</article-title>. In: <conf-name>2023 IEEE 14th International Symposium on Power Electronics for Distributed Generation Systems (PEDG); 2023 Jun 9&#x2013;12; Shanghai, China</conf-name>. doi:<pub-id pub-id-type="doi">10.1109/PEDG56097.2023.10215140</pub-id>.</mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wang</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Yu</surname> <given-names>X</given-names></string-name>, <string-name><surname>Xue</surname> <given-names>P</given-names></string-name>, <string-name><surname>Qu</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Ju</surname> <given-names>L</given-names></string-name></person-group>. <article-title>Research on medical security system based on zero trust</article-title>. <source>Sensors</source>. <year>2023</year>;<volume>23</volume>(<issue>7</issue>):<fpage>3774</fpage>. doi:<pub-id pub-id-type="doi">10.3390/s23073774</pub-id>; <pub-id pub-id-type="pmid">37050834</pub-id></mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Wei</surname> <given-names>Q</given-names></string-name></person-group>. <article-title>Analysis of the role of computer big data and cloud computing in information security</article-title>. In: <conf-name>2023 International Conference on Networking, Informatics and Computing (ICNETIC); 2023 May 29&#x2013;31; Palermo, Italy</conf-name>. doi:<pub-id pub-id-type="doi">10.1109/ICNETIC59568.2023.00031</pub-id>.</mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Tiwari</surname> <given-names>A</given-names></string-name>, <string-name><surname>Patel</surname> <given-names>PJ</given-names></string-name>, <string-name><surname>Sharma</surname> <given-names>DP</given-names></string-name></person-group>. <article-title>Vulnerability assessment and penetration testing approach towards cloud-based application and related services</article-title>. <source>Int J Sci Res Sci Eng Technol</source>. <year>2021</year>;<volume>2021</volume>:<fpage>395</fpage>&#x2013;<lpage>403</lpage>. doi:<pub-id pub-id-type="doi">10.32628/ijsrset218346</pub-id>.</mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Tsai</surname> <given-names>M</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>S</given-names></string-name>, <string-name><surname>Shieh</surname> <given-names>SW</given-names></string-name></person-group>. <article-title>Strategy for implementing of zero trust architecture</article-title>. <source>IEEE Trans Reliab</source>. <year>2024</year>;<volume>73</volume>(<issue>1</issue>):<fpage>93</fpage>&#x2013;<lpage>100</lpage>. doi:<pub-id pub-id-type="doi">10.1109/TR.2023.3345665</pub-id>.</mixed-citation></ref>
</ref-list>
</back></article>