DECONSTRUCTING THE NETWORK PERIMETER: A CONTINUOUS AUTHENTICATION FRAMEWORK FOR ZERO TRUST ARCHITECTURE IN CLOUD-NATIVE ENVIRONMENTS

Abdillah Imam Julianto (1), Amimul Ummah Bay (2), Mahendra Mahendra (3)
(1) Politeknik Angkatan LautID Indonesia,
(2) Politeknik Angkatan LautID Indonesia,
(3) Politeknik Angkatan LautID Indonesia

Abstract

Cloud-native computing has weakened the traditional network perimeter by distributing identities, workloads, applications, and data across dynamic infrastructures where successful login no longer guarantees continuing trust. This study develops and evaluates a continuous authentication framework for Zero Trust Architecture that dynamically reassesses trust throughout active sessions. A design science approach combined with controlled experimentation was employed using 1,200 authenticated sessions, including 800 legitimate and 400 adversarial scenarios involving token hijacking, session replay, privilege escalation, compromised devices, lateral movement, and anomalous API activity. The framework integrated identity confidence, behavioral consistency, device posture, contextual risk, workload telemetry, and resource sensitivity into adaptive trust scoring and graduated enforcement. Results showed that continuous authentication achieved a 93.0% detection rate, 91.9% precision, 93.0% recall, and a 92.4% F1-score, while reducing mean compromised-session exposure from 11.8 to 1.9 minutes. Moderate increases in latency and computational overhead remained operationally acceptable, and false-positive rates did not increase significantly. Improvements were strongest against post-authentication compromise and identity misuse. The study concludes that Zero Trust is more effectively implemented as a dynamic, revocable, and context-sensitive trust process than as repeated static authentication. Continuous authentication therefore provides a practical mechanism for protecting both human and machine identities in decentralized cloud-native environments.

Full text article

Generated from XML file

References

Abdelaziz, O. M., & Aslan, H. K. (2025). A Unified Security Operations Center and Zero Trust Architecture Framework for Adaptive IoT Threat Mitigation. 2025 International Mobile, Intelligent, and Ubiquitous Computing Conference (MIUCC), 1–8. https://doi.org/10.1109/MIUCC66482.2025.11196839

Aftab, S. (2026). AI-Augmented Zero Trust Security Framework for Conversational AI Systems: A Behavioral Analytics Approach. 2026 International Conference on Electrical/Electronics, Robotics, Artificial Intelligence, and Informatics (ICERAI), 1–6. https://doi.org/10.1109/ICERAI69511.2026.11494527

Alang, K., Peta, S. B., Pai, R. R., & Patil, B. (2025). Scalable Cloud Architectures for Efficient Processing of Multi-Structured Big Data. 2025 Global Conference in Emerging Technology (GINOTECH), 1–6. https://doi.org/10.1109/GINOTECH63460.2025.11077101

Alapati, N. K., & Dhanasekaran, S. (2025). Addressing Data Quality and Consistency Issues in Cloud-Based Big Data Environments. 2025 International Conference on Networks and Cryptology (NETCRYPT), 458–462. https://doi.org/10.1109/NETCRYPT65877.2025.11102213

Ali, B., & Dib, O. A. (2026). The Next Frontier of Cybersecurity: Zero Trust for Enterprise IoT Ecosystems. In M. Trabelsi, M. Khan, Z. Bouida, & M. Murugappan (Eds.), Proceedings of the 2nd Symposium on Smart, Sustainable, and Secure Internet of Things (Vol. 1513, pp. 1–7). Springer Nature Singapore. https://doi.org/10.1007/978-981-95-5136-1_1

Alnaim, A. K., & Alwakeel, A. M. (2025). Zero Trust Strategies for Cyber-Physical Systems in 6G Networks. Mathematics, 13(7), 1108. https://doi.org/10.3390/math13071108

Al-Said Ahmad, A., Al-Qora’n, L. F., & Zayed, A. (2024). Exploring the impact of chaos engineering with various user loads on cloud native applications: An exploratory empirical study. Computing, 106(7), 2389–2425. https://doi.org/10.1007/s00607-024-01292-z

Alshehri, A. M., Atawneh, S. H., Al Bazar, H., & Mallouhy, R. E. (2026). Enhancing the Adoption of Zero Trust in Organizations Using Machine Learning. Future Internet, 18(6), 278. https://doi.org/10.3390/fi18060278

Ben-Shimol, L., Lavi, D., Klevansky, E., Brodt, O., Mimran, D., Elovici, Y., & Shabtai, A. (2025). Detection of compromised functions in a serverless cloud environment. Computers & Security, 150, 104261. https://doi.org/10.1016/j.cose.2024.104261

Camargo, J. S., Rezazadeh, F., Chergui, H., Siddiqui, S., & Liu, L. (2025). Towards Cloud-Native Agentic Protocol Learning for Conflict-Free 6G: A Case Study on Inter-Slice Resource Allocation. 2025 Joint European Conference on Networks and Communications & 6G Summit (EuCNC/6G Summit), 43–48. https://doi.org/10.1109/EuCNC/6GSummit63408.2025.11036996

Chen, B., & Ge, W. (2024). Design and optimization strategy of electricity marketing information system supported by cloud computing platform. Energy Informatics, 7(1), 67. https://doi.org/10.1186/s42162-024-00366-8

Choi, H.-J., Kim, J.-H., Lee, J.-H., Han, J.-Y., & Kim, W.-S. (2025). Adaptive Microservice Architecture and Service Orchestration Considering Resource Balance to Support Multi-User Cloud VR. Electronics, 14(7), 1249. https://doi.org/10.3390/electronics14071249

Desai, V., H N, S., U, S., Kumar, K. A., C, B., & U, C. (2026). Next-Gen Secure Access Using Intelligent Zero Trust Network Architecture. 2026 IEEE Global Symposium on Emerging and Communication Technologies (GSEACT), 1–6. https://doi.org/10.1109/GSEACT68539.2026.11620242

Devarajulu, V. S., Kanipakam, S., & Kavarakuntla, T. (2025). Explainable Anomaly Detection in Cloud-Native Systems via RAG-Enhanced Vector Retrieval. 2025 6th International Conference on Information Science, Parallel and Distributed Systems (ISPDS), 181–185. https://doi.org/10.1109/ISPDS67367.2025.11391017

Dube, A., Mpande, B., Dzehonye, F., Chazuza, T., & Ndlovu, B. (2026). Zero Trust Architecture: Redefining Security in the Digital World. In V. Bhateja, J. Anguera, N. Mostafa, & A. Ghosh (Eds.), Advances in Micro-Electronics, Embedded Systems and IoT (Vol. 1600, pp. 26–39). Springer Nature Switzerland. https://doi.org/10.1007/978-3-032-20533-9_3

Farhan, M., Rajapakshe, M., Bin Sulaiman, R., Aljaidi, M., Butt, U., Ahmad, M., Hadi, W., & Alshammari, A. A. (2026). ZTF-SF: A Zero-Trust Blockchain-Enabled IIoT Framework for Secure Smart Factories. 2026 2nd International Conference on Computational Intelligence Approaches and Applications (ICCIAA), 1–9. https://doi.org/10.1109/ICCIAA68481.2026.11543806

Fayaz, K., Chakradhar, V., & D, U. (2026). API Security with JWT Authentication and Reputation Based Monitoring System. 2026 Fifth International Conference on Power, Control and Computing Technologies (ICPC2T), 746–751. https://doi.org/10.1109/ICPC2T68221.2026.11646386

Galij, S., Pawlak, G., & Grzyb, S. (2025). Evaluating the Performance Impact of Data Sovereignty Features on Data Spaces. Applied Sciences, 15(17), 9841. https://doi.org/10.3390/app15179841

Ganesh, C., Garg, R., Sreenivas, N., Saikia, H., Abdulhasan, M. M., & Dhanraj, J. A. (2025). Design and Implementation of AI-Based Decision Support Systems for Enhancing Strategic Business Operations. 2025 IEEE International Conference on Innovate for Humanitarian: Tech Solutions for Global Challenge (ICIH), 1–6. https://doi.org/10.1109/ICIH67754.2025.11608700

Guha, D., Saw, S. K., Mukherjee, P., Singh, G., & Satyam. (2025). A Practical Implementation of Zero Trust Architecture for Securing Web-Based Applications. 2025 International Conference on Advancements in Smart, Secure and Intelligent Computing (ASSIC), 1–6. https://doi.org/10.1109/ASSIC64892.2025.11158196

Ishaque, M., Albatati, H., & Nofal, M. (2025). AI-Based Zero Trust Architecture for Cognitive City Networks. 2025 2nd International Conference on Advanced Innovations in Smart Cities (ICAISC), 01–14. https://doi.org/10.1109/ICAISC64594.2025.10959378

Jayasri, T., Jenis, M. R. A., Aswathy, P. B., Manoranjitham, S., George, C., & Senthilkumar, R. (2025). Using Context-Aware and Identity-First Defense in Zero Trust Security Architecture to Protect Cyberspace. 2025 3rd International Conference on Intelligent Cyber Physical Systems and Internet of Things (ICoICI), 351–356. https://doi.org/10.1109/ICoICI65217.2025.11254505

K, R., Sulthana, S., Krishna, R. P., Naik, S. G., & Kavya. (2026). Redefining Trust Boundaries: A Holistic Synthesis of Zero-Trust Architecture Across Emerging Ecosystems. 2026 IEEE International Conference on Emerging Synergy Science and Technology (ICESST), 1–5. https://doi.org/10.1109/ICESST69086.2026.11582862

Kande, R. (2026). Zero-Trust Healthcare Clouds: AI-Enhanced Identity, Threat Detection, and Automated Compliance Enforcement. 2026 Third International Conference on Networking and Communications (ICNWC), 1–7. https://doi.org/10.1109/ICNWC68145.2026.11518125

Katipoglu, G., Utku, S., Mijailovi?, I., Meki?, E., Avdi?, D., & Mili?, P. (2024). Action Research Approach to Analysis of Teaching of Blockchain Web 3.0 Application Based on MACH Architecture. Applied Sciences, 14(23), 11158. https://doi.org/10.3390/app142311158

Lee, D., Park, S., & Lee, B. (2024). Dynamic Traffic Load Rebalancing for Hardware-accelerated 6G UPF Resilient Architecture. 2024 IEEE International Performance, Computing, and Communications Conference (IPCCC), 1–7. https://doi.org/10.1109/IPCCC59868.2024.10850096

Lingam, R., Nagi, S., Chigurupati, M., & Myneni, B. T. (2026). Resilient DevSecOps: Self-Healing Cloud-Native Systems via SRE-Driven AI Threat Detection and Response. 2026 International Conference on Smart Futuristic Technology, 1–6. https://doi.org/10.1109/ICSFT66733.2026.11508049

Malamuthu, B. K., Pandi, V. S., D, S., Jaber, A. H., Giri, J., & P, R. Y. (2025). Examining Multi-Cloud Architectures to Provide Enterprises with Resilient, Scalable, and Economical Cloud Computing Solutions. 2025 International Conference on Engineering Innovations and Technologies (ICoEIT), 970–975. https://doi.org/10.1109/ICoEIT63558.2025.11211532

Mittal, G., & Ghosh, S. (2025). Trust for Critical Power Infrastructure Cybersecurity Framework for Modern OT Environments. 2025 International Conference on Intelligent Digitization of Systems and Services (IDSS), 129–134. https://doi.org/10.1109/IDSS67199.2025.11398188

Montin, E., Nguyen, X. T., & Lattanzi, R. (2026). MR Optimum: A web-based open-source tool for standardized signal-to-noise ratio evaluation in MRI. Computer Methods and Programs in Biomedicine Update, 9, 100235. https://doi.org/10.1016/j.cmpbup.2026.100235

Nurtas, M., Nurakynov, S., Altaibek, A., Mergembayeva, A., & Mohammed, M. A. (2025). Satellite based deep learning approaches for detecting environmental disasters across Kazakhstan. Discover Applied Sciences, 8(2), 144. https://doi.org/10.1007/s42452-025-08133-4

Paya, A., Vicente-García, & Gómez, A. (2025). Enhancing software-defined perimeters with integrated identity solutions and threat detection for robust zero trust security. International Journal of Information Security, 24(4), 178. https://doi.org/10.1007/s10207-025-01099-9

Pule, B., Nleya, B., & Sibiya, K. (2026). A Zero Trust Driven Federative Learning Algorithm for Privacy Enhancement. Applied Sciences, 16(8), 3872. https://doi.org/10.3390/app16083872

R, H., Marothia, F., Nag, S., Gangrade, D., Govindasamy, D., & P, P. (2025). A Comprehensive Survey on Zero Trust Architecture in IoT Networks. 2025 IEEE International Conference on Internet of Things and Intelligence Systems (IoTaIS), 90–96. https://doi.org/10.1109/IoTaIS67227.2025.11282130

Raju, V., Ujang, A. H., An, Y. D., Bellamkonda, S., Yeruva, L. A., & Chawla, N. (2026). Secure-by-Design Cloud Architectures: Integrating Machine Learning with Zero Trust Security Models. 2026 Innovations in Machine, Engineering, and Digital Conference (IMED), 1–6. https://doi.org/10.1109/IMED68921.2026.11484318

Rana, R., & Bhambri, P. (2026). Zero-Trust for Immersive Systems and Spatial Computing: In O. Almomani, A. Almomani, & M. Alauthman (Eds.), Advances in Computational Intelligence and Robotics (pp. 279–340). IGI Global Scientific Publishing. https://doi.org/10.4018/979-8-3373-7882-4.ch010

Sable, N. M., Sharma, V. K., & Manjre, B. (2025). Design of an Iterative Method for Zero-Day Attack Detection Using Adversarial Graph Temporal Convolutional Networks and Federated Learning. In A. Bagwari, J. L. V. Barbosa, E. Babulak, & D. S. Chauhan (Eds.), Emerging Wireless Technologies and Sciences (Vol. 2399, pp. 49–63). Springer Nature Switzerland. https://doi.org/10.1007/978-3-031-87886-2_4

Shin, D., Kim, J., Pawana, I. W. A. J., & You, I. (2025). Enhancing cloud-native DevSecOps: A Zero Trust approach for the financial sector. Computer Standards & Interfaces, 93, 103975. https://doi.org/10.1016/j.csi.2025.103975

Singh, A. (2025). Enhancing 5G Security Through Zero Trust Architecture: A Threat-Centric Analysis of Critical Interfaces. 2025 IEEE 4th International Conference on Intelligent Reality (ICIR), 1–6. https://doi.org/10.1109/ICIR68135.2025.11361566

Singh, S. (2025). Zero-Trust Interconnect Framework for Secure Multi-Cloud Connectivity. 2025 International Conference on Computational Engineering, Sensing Technology and Management (ICCETM), 1–6. https://doi.org/10.1109/ICCETM66557.2025.11557841

Somayajula, R., Pai, R. R., Sajanraj, N., & Shah, K. (2025). Zero-ETL Architectures for AI Workloads Direct ML Model Access on Cloud-Native OLAP Systems. 2025 International Conference on Computing Technologies (ICOCT), 1–7. https://doi.org/10.1109/ICOCT64433.2025.11118928

Sultana, N., Miah, M. K., Ahmed, K. R., Goyal, S. K., Ali, A. H. M. M., & Karim, M. R. (2026). Zero-Trust Access Control Via Blockchain-Backed Identity and AI-Based Anomaly Detection. 2026 International Conference on Signal Analysis for Smart Systems (SIGNASS), 1–6. https://doi.org/10.1109/SIGNASS67826.2026.11480024

Vikas, Wahi, C., Sagar, B. B., & Manjul, M. (2025). Zero Trust for Secure Wireless Sensor Networks. 2025 International Conference on Networks and Cryptology (NETCRYPT), 42–46. https://doi.org/10.1109/NETCRYPT65877.2025.11102154

Viswanathan, J., N, D. Kumar., & Kumar, S. U. (2024). Zero Trust Security for Web Applications in Microservice-Based Environments. 2024 First International Conference on Data, Computation and Communication (ICDCC), 488–494. https://doi.org/10.1109/ICDCC62744.2024.10960955

Vusumuzi, M., & Godwin, M. (2025). AI-Driven Zero-Trust Models for Blockchain-Supported Healthcare Ecosystems. Proceedings of the 2025 International Conference on Artificial Intelligence and Its Applications, 1–11. https://doi.org/10.1145/3774791.3774801

Yashu, F., Rochester, S. M., & Saqib, M. (2025). Optimizing Intra-Container Communication with Memory Protection Keys: A Novel Approach to Secure and Efficient Microservice Interaction. 2025 International Conference on Business Intelligence for Technology Innovation (ICBITI), 1–7. https://doi.org/10.1109/ICBITI65527.2025.11501025

Yue, P., Wang, K., Wu, H., & Liu, R. (2025). Recent progress and technical practices of GIServices. Chinese Science Bulletin, 70(30), 5163–5179. https://doi.org/10.1360/TB-2025-0107

Zeydan, E., Arslan, S., & Turk, Y. (2026). A Cloud Native Journey for Telecommunication Networks: Components, Applications and Open Challenges. ACM Computing Surveys, 58(10), 1–38. https://doi.org/10.1145/3801492

Authors

Abdillah Imam Julianto
abdillahimamjulianto@gmail.com (Primary Contact)
Amimul Ummah Bay
Mahendra Mahendra
Julianto, A. I., Bay, A. U., & Mahendra, M. (2026). DECONSTRUCTING THE NETWORK PERIMETER: A CONTINUOUS AUTHENTICATION FRAMEWORK FOR ZERO TRUST ARCHITECTURE IN CLOUD-NATIVE ENVIRONMENTS. Journal of Computer Science Advancements, 4(4), 308–328. https://doi.org/10.70177/jsca.v4i4.4352

Article Details

Similar Articles

1 2 3 4 5 6 > >> 

You may also start an advanced similarity search for this article.