Home / Current Issue / Paper 1711893
AI-Driven Zero-Trust Security Framework for Detecting Advanced Persistent Threats in Cloud Environments
Subject area: Science,Engineering and Technology · Area of research: Artificial Intelligence
Abstract
The growing complexity of Advanced Persistent Threats (APTs) poses a serious concern for cloud systems that rely on distributed resources and virtualized services. Conventional perimeter-based defenses and rule-based mechanisms are not always effective at identifying stealthy APT campaigns that dynamically evolve in multi-tenancy environments. This paper presents a Zero-Trust Security Framework based on AI that combines hybrid machine learning models with adaptive policy automation to identify, respond to, and mitigate APTs in multi-cloud ecosystems. The framework is based on the Extreme Gradient Boosting (XGBoost) to analyze structured log and network data, and a Deep Neural Network (DNN) to identify behavioral and temporal abnormalities that can be interpreted as the presence of malicious persistence or lateral movement. Based on the resulting model, trust scores are continually recalculated and dynamic access controls are imposed, consistent with Zero-Trust principles. One case study run on AWS and Azure infrastructure tests performance metrics, including detection accuracy, latency, and false-positive rate, under simulated attacks. The experimental findings suggest that the proposed framework can dramatically improve anomaly detection performance and response time compared to traditional models. Also, automated trust recalibration and microsegmentation enhance the system's overall resilience and compliance. This study demonstrates the potential of integrating artificial intelligence into Zero-Trust architectures to proactively detect and prevent APTs, providing a scalable, intelligent approach to securing cloud-native infrastructure.
Keywords
Artificial Intelligence (AI); Zero-Trust Architecture (ZTA); Advanced Persistent Threats (APTs); Cloud Security; Machine Learning; Behavioral Analytics; XGBoost; Deep Neural Networks; Adaptive Access Control; Policy Automation
References
[1] Alojail, M., & Bhatia, S. (2020). A Novel Technique for Behavioral Analytics Using Ensemble Learning Algorithms in E-Commerce. IEEE Access, 8, 150072–150080. https://doi.org/10.1109/ACCESS.2020.3016419
[2] Bahrami, M., Bozkaya, B., & Balcisoy, S. (2020). Using Behavioral Analytics to Predict Customer Invoice Payment. Big Data, 8(1), 25–37. https://doi.org/10.1089/big.2018.0116
[3] Buhrmester, V., Münch, D., & Arens, M. (2021). Analysis of Explainers of Black Box Deep Neural Networks for Computer Vision: A Survey. Machine Learning and Knowledge Extraction, 3(4), 966–989. https://doi.org/10.3390/make3040048
[4] Carlton, M., & Levy, Y. (2017). Cybersecurity skills: Foundational theory and the cornerstone of advanced persistent threats (APTs) mitigation. Online Journal of Applied Knowledge Management, 5(2), 16–28. https://doi.org/10.36965/ojakm.2017.5(2)16-28
[5] Chauhan, M., & Shiaeles, S. (2023, September 1). An Analysis of Cloud Security Frameworks, Problems, and Proposed Solutions. Network. Multidisciplinary Digital Publishing Institute (MDPI). https://doi.org/10.3390/network3030018
[6] Cug, J., Kubala, P., & Pera, A. (2023). Generative Artificial Intelligence and Virtual Recruitment Tools, Wearable Self-Tracking and Augmented Reality Devices, and Multimodal Behavioral Analytics in Virtual Workplaces. Analysis and Metaphysics, 22. https://doi.org/10.22381/am2220238
[7] Fernandez, E. B., & Brazhuk, A. (2022). A Critical Analysis of Zero Trust Architecture (ZTA). SSRN Electronic Journal. https://doi.org/10.2139/ssrn.4210104
[8] Fernandez, E. B., & Brazhuk, A. (2024). A critical analysis of Zero Trust Architecture (ZTA). Computer Standards and Interfaces, 89. https://doi.org/10.1016/j.csi.2024.103832
[9] Gawlikowski, J., Tassi, C. R. N., Ali, M., Lee, J., Humt, M., Feng, J., … Zhu, X. X. (2023). A survey of uncertainty in deep neural networks. Artificial Intelligence Review, 56, 1513–1589. https://doi.org/10.1007/s10462-023-10562-9
[10] Haleem, A., Javaid, M., Asim Qadri, M., Pratap Singh, R., & Suman, R. (2022, January 1). Artificial intelligence (AI) applications for marketing: A literature-based study. International Journal of Intelligent Networks. KeAi Communications Co. https://doi.org/10.1016/j.ijin.2022.08.005
[11] Horodyski, P. (2023). Recruiter's perception of artificial intelligence (AI)-based tools in recruitment. Computers in Human Behavior Reports, 10. https://doi.org/10.1016/j.chbr.2023.100298
[12] Jabeur, S. B., Mefteh-Wali, S., & Viviani, J. L. (2024). Forecasting gold price with the XGBoost algorithm and SHAP interaction values. Annals of Operations Research, 334(1–3), 679–699. https://doi.org/10.1007/s10479-021-04187-w
[13] Kalaiprasath, R., Elankavi, R., & Udayakumar, R. (2017). Cloud security and compliance - A semantic approach in end-to-end security. International Journal on Smart Sensing and Intelligent Systems, 2017(Special issue), 482–494. https://doi.org/10.21307/ijssis-2017-265
[14] Khalid, M. N. A., Al-Kadhimi, A. A., & Singh, M. M. (2023, March 1). Recent Developments in Game-Theory Approaches for the Detection and Defense against Advanced Persistent Threats (APTs): A Systematic Review. Mathematics. MDPI. https://doi.org/10.3390/math11061353
[15] Kovacova, M., Horak, J., & Higgins, M. (2022). Behavioral Analytics, Immersive Technologies, and Machine Vision Algorithms in the Web3-powered Metaverse World. Linguistic and Philosophical Investigations, 21, 57–72. https://doi.org/10.22381/lpi2120224
[16] Kumar, R., & Goyal, R. (2019). On cloud security requirements, threats, vulnerabilities, and countermeasures: A survey. Computer Science Review. Elsevier Ireland Ltd. https://doi.org/10.1016/j.cosrev.2019.05.002
[17] Mintz, Y., Aswani, A., Kaminsky, P., Flowers, E., & Fukuoka, Y. (2023). Behavioral analytics for myopic agents. European Journal of Operational Research, 310(2), 793–811. https://doi.org/10.1016/j.ejor.2023.03.034
[18] Moothedath, S., Sahabandu, D., Allen, J., Clark, A., Bushnell, L., Lee, W., & Poovendran, R. (2020). A Game-Theoretic Approach for Dynamic Information Flow Tracking to Detect Multistage Advanced Persistent Threats. IEEE Transactions on Automatic Control, 65(12), 5248–5263. https://doi.org/10.1109/TAC.2020.2976040
[19] Nassif, A. B., Talib, M. A., Nasir, Q., Albadani, H., & Dakalbab, F. M. (2021). Machine Learning for Cloud Security: A Systematic Review. IEEE Access. Institute of Electrical and Electronics Engineers Inc. https://doi.org/10.1109/ACCESS.2021.3054129
[20] Phiayura, P., & Teerakanok, S. (2023). A Comprehensive Framework for Migrating to Zero Trust Architecture. IEEE Access, 11, 19487–19511. https://doi.org/10.1109/ACCESS.2023.3248622
[21] Salahuddin, Z., Woodruff, H. C., Chatterjee, A., & Lambin, P. (2022, January 1). Transparency of deep neural networks for medical image analysis: A review of interpretability methods. Computers in Biology and Medicine. Elsevier Ltd. https://doi.org/10.1016/j.compbiomed.2021.105111
[22] Shah, S. W., Syed, N. F., Shaghaghi, A., Anwar, A., Baig, Z., & Doss, R. (2021). LCDA: Lightweight Continuous Device-to-Device Authentication for a Zero Trust Architecture (ZTA). Computers and Security, 108. https://doi.org/10.1016/j.cose.2021.102351
[23] Singh, A., & Chatterjee, K. (2017, February 1). Cloud security issues and challenges: A survey. Journal of Network and Computer Applications. Academic Press. https://doi.org/10.1016/j.jnca.2016.11.027
[24] Su, J., & Zhong, Y. (2022). Artificial Intelligence (AI) in early childhood education: Curriculum design and future directions. Computers and Education: Artificial Intelligence, 3. https://doi.org/10.1016/j.caeai.2022.100072
[25] Syed, N. F., Shah, S. W., Shaghaghi, A., Anwar, A., Baig, Z., & Doss, R. (2022). Zero Trust Architecture (ZTA): A Comprehensive Survey. IEEE Access. Institute of Electrical and Electronics Engineers Inc. https://doi.org/10.1109/ACCESS.2022.3174679
[26] Tian, W., Du, M., Ji, X., Liu, G., Dai, Y., & Han, Z. (2021). Honeypot Detection Strategy against Advanced Persistent Threats in Industrial Internet of Things: A Prospect Theoretic Game. IEEE Internet of Things Journal, 8(24), 17372–17381. https://doi.org/10.1109/JIOT.2021.3080527
[27] Vaishya, R., Javaid, M., Khan, I. H., & Haleem, A. (2020). Artificial Intelligence (AI) applications for the COVID-19 pandemic. Diabetes and Metabolic Syndrome: Clinical Research and Reviews, 14(4), 337–339. https://doi.org/10.1016/j.dsx.2020.04.012
[28] Winkelman, J., Nguyen, D., Vansonnenberg, E., Kirk, A., & Lieberman, S. (2023, October 1). Artificial Intelligence (AI) in pediatric endocrinology. Journal of Pediatric Endocrinology and Metabolism. Walter de Gruyter GmbH. https://doi.org/10.1515/jpem-2023-0287
[29] Yuan, H., Xia, Y., Zhang, J., Yang, H., & Mahmoud, M. S. (2020). Stackelberg-Game-Based Defense Analysis against Advanced Persistent Threats on Cloud Control System. IEEE Transactions on Industrial Informatics, 16(3), 1571–1580. https://doi.org/10.1109/TII.2019.2925035
[30] Zhang, P., Jia, Y., & Shang, Y. (2022). Research and application of XGBoost in imbalanced data. International Journal of Distributed Sensor Networks, 18(6). https://doi.org/10.1177/15501329221106935
How to cite this paper
@article{1711893,
author = {Aidar Imashev},
title = {AI-Driven Zero-Trust Security Framework for Detecting Advanced Persistent Threats in Cloud Environments},
journal = {Iconic Research And Engineering Journals},
year = {2025},
volume = {9},
number = {5},
pages = {477-491},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1711893.pdf},
abstract = {The growing complexity of Advanced Persistent Threats (APTs) poses a serious concern for cloud systems that rely on distributed resources and virtualized services. Conventional perimeter-based defenses and rule-based mechanisms are not always effective at identifying stealthy APT campaigns that dynamically evolve in multi-tenancy environments. This paper presents a Zero-Trust Security Framework based on AI that combines hybrid machine learning models with adaptive policy automation to identify, respond to, and mitigate APTs in multi-cloud ecosystems. The framework is based on the Extreme Gradient Boosting (XGBoost) to analyze structured log and network data, and a Deep Neural Network (DNN) to identify behavioral and temporal abnormalities that can be interpreted as the presence of malicious persistence or lateral movement. Based on the resulting model, trust scores are continually recalculated and dynamic access controls are imposed, consistent with Zero-Trust principles. One case study run on AWS and Azure infrastructure tests performance metrics, including detection accuracy, latency, and false-positive rate, under simulated attacks. The experimental findings suggest that the proposed framework can dramatically improve anomaly detection performance and response time compared to traditional models. Also, automated trust recalibration and microsegmentation enhance the system's overall resilience and compliance. This study demonstrates the potential of integrating artificial intelligence into Zero-Trust architectures to proactively detect and prevent APTs, providing a scalable, intelligent approach to securing cloud-native infrastructure.},
keywords = {Artificial Intelligence (AI); Zero-Trust Architecture (ZTA); Advanced Persistent Threats (APTs); Cloud Security; Machine Learning; Behavioral Analytics; XGBoost; Deep Neural Networks; Adaptive Access Control; Policy Automation},
month = {November},
}