Intelligent Access Control and Risk Assessment Using AI for Zero Trust Cloud Security |
Author(s): |
| Suresh , St. George's Arts & Science College |
Keywords: |
| Zero Trust Architecture, Cloud Computing, Artificial Intelligence, Machine Learning, Dynamic Access Control, Cloud Security, Anomaly Detection, Risk-Based Authentication, Continuous Monitoring, Cybersecurity. |
Abstract |
|
Yoga Cloud computing has changed the way organizations store, process, and access digital resources. The movement from traditional enterprise networks toward cloud, hybrid-cloud, multi-cloud, and remote-access environments has also weakened the effectiveness of conventional perimeter-based security models. In a traditional security architecture, users and devices located inside an organizational network are often treated as relatively trusted. However, compromised credentials, insider threats, cloud misconfigurations, stolen sessions, malicious applications, and lateral movement attacks demonstrate that network location alone cannot be used as a reliable indicator of trust. Zero-Trust Architecture (ZTA) addresses this problem by assuming that no user, device, application, or network connection should receive implicit trust. Every access request must be authenticated, authorized, evaluated, and continuously monitored. NIST SP 800-207 establishes this resource-oriented approach to zero trust, while later NIST guidance specifically addresses cloud-native and multi-cloud environments. (NIST Computer Security Resource Center) Although Zero Trust provides a strong security foundation, conventional implementations may depend heavily on static rules, predefined policies, and manually configured access-control mechanisms. Such approaches may have difficulty responding to rapidly changing user behavior, device posture, workload characteristics, and attack patterns. Artificial intelligence provides an opportunity to make Zero Trust more adaptive by analyzing behavioral, contextual, identity, and network signals and dynamically estimating access risk. This paper proposes an AI-Driven Zero-Trust Security Framework for Cloud Computing (AI-ZTSCF) that combines continuous identity verification, device-posture assessment, contextual risk analysis, machine-learning-based anomaly detection, dynamic policy enforcement, micro-segmentation, and continuous monitoring. The proposed framework generates a dynamic risk score for every access request and uses this score to determine whether access should be granted, challenged, restricted, or denied. A machine-learning component identifies anomalous behavior, while a policy engine combines AI-generated risk with identity, device, resource sensitivity, location, session behavior, and threat-intelligence information. The framework is designed for cloud and multi-cloud environments and can be integrated with identity providers, API gateways, service meshes, security information and event management systems, and cloud-native monitoring tools. A prototype-oriented evaluation methodology is also presented using standard intrusion-detection and access-behavior datasets. Performance is evaluated using accuracy, precision, recall, F1-score, false-positive rate, detection latency, and access-decision latency. Illustrative results demonstrate how the proposed framework can be evaluated against conventional rule-based access control and machine-learning-only security models. The study concludes that combining AI with Zero Trust can provide a more adaptive and context-aware security architecture, while also highlighting challenges involving explainability, adversarial machine learning, privacy, computational overhead, model drift, and policy-management complexity. |
Other Details |
|
Paper ID: IJSRDV14I60026 Published in: Volume : 14, Issue : 6 Publication Date: 01/09/2026 Page(s): 57-61 |
Article Preview |
|
|
|
|
