arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

具备对抗鲁棒性评估的可解释自适应零信任框架(针对AWS)

Explainable Adaptive Zero Trust Framework for AWS with Adversarial Robustness Evaluation

Om Singh, Yagyaraj Pandey, Nandini Pathak

arXiv 2608.21477首次发表:更新:

发表机构

Dr. A.P.J. Abdul Kalam Technical University(Dr. A.P.J. Abdul Kalam 技术大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究针对AWS提出具备对抗鲁棒性评估的可解释自适应零信任框架(EAZTF),结合Isolation Forest与XGBoost评估行为特征,可实时判定会话状态,合规性与检测效率均优于传统方案。

AI 中文摘要

基于亚马逊云服务(AWS)构建的云环境存在结构性安全漏洞:一旦凭证通过身份验证,对应的会话通常在整个持续期间都被视为可信。当凭证被盗时,这一假设就会失效。我们提出可解释自适应零信任框架(EAZTF),这是一种云原生安全层,可在会话全程持续重新评估API操作的合法性。EAZTF结合孤立森林(Isolation Forest)与XGBoost,实时评估8个由CloudTrail和IAM衍生的行为特征,生成信任风险评分(TRS),用于判定会话是否继续、是否需要增强型多因素认证(MFA)或是否受限。每个决策都附带SHAP或LIME解释,为安全分析与合规性提供人类可读的审计记录。该框架还针对四种对抗性规避策略进行评估:凭证盗窃、行为模仿、API速率规避与权限提升。在包含8500条记录的合成CloudTrail数据集上的实验显示,孤立森林达到94.4%的精确率、91.2%的召回率和0.928的F1分数。在四种对抗场景中,平均检测率为91.0%,其中行为模仿最难,检测率为83.9%。SHAP分析将IP信誉、登录时间偏差和API调用速度识别为三个主导特征。结构化NIST SP 800-207自评给出EAZTF平均合规得分为93%,而传统边界基线为38%。平均检测时间从数小时缩短至不到一分钟。由于评估使用合成数据,这些结果应视为指示性的,而非经过验证的生产环境性能。

英文摘要

Cloud environments built on Amazon Web Services face a structural security vulnerability: once a credential passes authentication, the resulting session is often treated as trusted for its entire duration. This assumption fails when credentials are stolen. We introduce the Explainable Adaptive Zero Trust Framework (EAZTF), a cloud-native security layer that continuously reevaluates the legitimacy of API actions throughout a session. EAZTF combines Isolation Forest and XGBoost to evaluate eight CloudTrail and IAM-derived behavioral features in real time and produce a Trust Risk Score (TRS) that determines whether a session continues, requires step-up MFA, or is restricted. Each decision is accompanied by a SHAP or LIME explanation, providing human-readable audit records for security analysis and compliance. The framework is also evaluated against four adversarial evasion strategies: credential theft, behavioral mimicry, API rate evasion, and privilege escalation. Experiments on an 8,500-record synthetic CloudTrail dataset show that Isolation Forest achieves 94.4% precision, 91.2% recall, and an F1 score of 0.928. Across the four adversarial scenarios, the mean detection rate is 91.0%, with behavioral mimicry being the most difficult at 83.9%. SHAP analysis identifies IP reputation, login-time deviation, and API call velocity as the three dominant features. A structured NIST SP 800-207 self-assessment gives EAZTF a mean compliance score of 93%, compared with 38% for a traditional perimeter baseline. Mean time to detect decreases from hours to under one minute. Because the evaluation uses synthetic data, these results should be interpreted as indicative rather than validated production performance.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑