Policy-Feedback Temporal Attack Graphs for Typed Multi-Cloud Zero-Trust Analysis
编号:96
访问权限:仅限参会人
更新:2026-10-04 23:39:31 浏览:12次
Online
摘要
Multi-cloud estates expose lateral-movement paths whose reachability changes as Zero-Trust Architecture (ZTA) policies evaluate trust, refresh authorization, and isolate suspicious services, yet prior models represent propagation over a largely fixed graph or access decisions without propagation, so the closed loop between them is rarely expressed. We present the Policy-Feedback Temporal Attack Graph (PF-TAG), a transition system in which compromise state, node trust, edge policy freshness, and edge authorization co-evolve over nodes typed by provider, region, role, and compliance class: a compromise at t alters authorization at t + 1 and therefore reachability at t + 2. It is evaluated over a comprehensive suite (N = 1,000), a 10- topology resampling (300 runs per scenario), four propagationonly epidemiological references, and a live Istio/OPA testbed. Medium-gain PF-TAG holds mean peak infection to 85.5 against 464.7 for No-ZTA; against non-ZTA disease references (603.6– 811.6), this isolates the access-control effect. The ordering is stable in 10/10 topologies; strict static ZTA suppresses peaks further (7.0 nodes), and legacy placement and token bypass raise modeled peak infection by 7.0× and 1.8×. Feedback thus offers no peak suppression advantage over a well-tuned strict policy on a known topology, but instead makes policy churn, verification overhead, false-block cost, and the model’s own failure conditions jointly observable. These are modelbased results with component-level live evidence, not production validation.
关键词
Zero-Trust Architecture,temporal attack graph,multi-cloud security,policy feedback,dynamic trust,microsegmentation
稿件作者
Thanh An Vu
University of Wisconsin-Stout Polytechnic
Tran Duc Le
University of Wisconsin-Stout Polytechnic
Truong Duy Dinh
Posts and Telecommunications Institute of Technology
发表评论