International Peer-Reviewed JournalOpen AccessISSN 2456-8880
irejournals@gmail.com+91-7433024337

Home / Current Issue / Paper 1717535

1717535PublishedVol 9 · Issue 10

Evolutionary Computation-Enhanced White-Box Penetration Testing for Lateral-Movement Prevention in Zero-Trust Architectures

Marcelo Araujo

Subject area: Science,Engineering and Technology  ·  Area of research: Sciences

DOI: https://doi.org/10.64388/IREV9I10-1717535

Abstract

Preventing lateral movement remains a central cybersecurity challenge even in environments designed according to Zero Trust principles. Although this paradigm reduces implicit trust and enforces continuous verification, its effectiveness ultimately depends on access-policy quality, identity-to-resource segmentation, and the ability to detect abusive chains built from seemingly legitimate permissions. In parallel, recent automated penetration-testing research has advanced through reinforcement learning, graph-based modeling, and simulation frameworks for exploring complex attack surfaces [1-4]. Building on this state of the art, this article proposes a conceptual white-box penetration-testing framework for Zero-Trust architectures in which evolutionary algorithms perform global search over the internal blueprint of the environment, while reinforcement learning adaptively refines promising action sequences. The model assumes authorized defensive access to ZTNA policies, identity and privilege graphs, workload dependencies, and continuous-verification logs. Its fitness function is multi-objective and jointly considers success probability, stealth, and evasion rate. We argue that this combination may improve the identification of plausible lateral-movement routes and generate more useful remediation outputs, provided that it is applied in controlled environments with telemetry sufficiently faithful to the real system.

Keywords

Automated Penetration Testing, Evolutionary Computation, Reinforcement Learning, Lateral Movement, Zero Trust.

How to cite this paper

Marcelo Araujo "Evolutionary Computation-Enhanced White-Box Penetration Testing for Lateral-Movement Prevention in Zero-Trust Architectures" Iconic Research And Engineering Journals Volume 9 Issue 10 2026 Page 4275-4279 https://doi.org/10.64388/IREV9I10-1717535
Marcelo Araujo "Evolutionary Computation-Enhanced White-Box Penetration Testing for Lateral-Movement Prevention in Zero-Trust Architectures" Iconic Research And Engineering Journals, vol. 9, no. 10, Apr. 2026, doi: https://doi.org/10.64388/IREV9I10-1717535
Marcelo Araujo (2026). Evolutionary Computation-Enhanced White-Box Penetration Testing for Lateral-Movement Prevention in Zero-Trust Architectures. Iconic Research And Engineering Journals, 9(10). doi: https://doi.org/10.64388/IREV9I10-1717535
Marcelo Araujo "Evolutionary Computation-Enhanced White-Box Penetration Testing for Lateral-Movement Prevention in Zero-Trust Architectures" Iconic Research And Engineering Journals, vol. 9, no. 10, Apr. 2026. Crossref, https://doi.org/10.64388/IREV9I10-1717535
@article{1717535,
      author = {Marcelo Araujo},
      title = {Evolutionary Computation-Enhanced White-Box Penetration Testing for Lateral-Movement Prevention in Zero-Trust Architectures},
      journal = {Iconic Research And Engineering Journals},
      year = {2026},
      volume = {9},
      number = {10},
      pages = {4275-4279},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1717535.pdf},
      abstract = {Preventing lateral movement remains a central cybersecurity challenge even in environments designed according to Zero Trust principles. Although this paradigm reduces implicit trust and enforces continuous verification, its effectiveness ultimately depends on access-policy quality, identity-to-resource segmentation, and the ability to detect abusive chains built from seemingly legitimate permissions. In parallel, recent automated penetration-testing research has advanced through reinforcement learning, graph-based modeling, and simulation frameworks for exploring complex attack surfaces [1-4]. Building on this state of the art, this article proposes a conceptual white-box penetration-testing framework for Zero-Trust architectures in which evolutionary algorithms perform global search over the internal blueprint of the environment, while reinforcement learning adaptively refines promising action sequences. The model assumes authorized defensive access to ZTNA policies, identity and privilege graphs, workload dependencies, and continuous-verification logs. Its fitness function is multi-objective and jointly considers success probability, stealth, and evasion rate. We argue that this combination may improve the identification of plausible lateral-movement routes and generate more useful remediation outputs, provided that it is applied in controlled environments with telemetry sufficiently faithful to the real system.},
      keywords = {Automated Penetration Testing, Evolutionary Computation, Reinforcement Learning, Lateral Movement, Zero Trust.},
      month = {April},
      doi = {https://doi.org/10.64388/IREV9I10-1717535}
  }