ZERO-TRUST ACCESS MANAGEMENT MODELS FOR SECURING CLOUD-NATIVE APPLICATIONS

Main Article Content

Sandeep Dommari

Abstract

This paper presents an uncertainty-aware zero-trust access decision framework evaluated on cloud-native Kubernetes and identity logs under strict per-request latency budgets. Although zero-trust guidance is widespread, comparable evidence under leakage-proof temporal validation and deployment-realistic inference constraints remains limited. The approach trained supervised tabular and graph-augmented models with calibrated probabilities and rigorous leakage controls, benchmarking against Open Policy Agent (OPA) rules, Xgboost, and an Ft Transformer Tabular variant using temporal splits and leave-site-out testing. On the test split, Area Under the Precision-Recall Curve (AUPRC) was 0.61 +/- 0.01 for Ft Transformer Graph, exceeding Xgboost at 0.55 +/- 0.01, and p95 latency measured 9.3 +/- 0.3 ms with sustained 3400 +/- 100 requests per second (RPS) at batch size one. The parts are familiar; the sequencing is not, combining calibrated thresholds, leakage-checked temporal evaluation, and external validation to support least-privilege enforcement at scale. These results indicate deployability for security operators implementing deny-by-default policy gates in Kubernetes clusters.

Article Details

Section
Articles