AI-BASED EMPOWERING OF COMPLIANCE WITH ZERO TRUST PRINCIPLES IN CORPORATE NETWORK ARCHITECTURE
DOI:
https://doi.org/10.28925/2663-4023.2026.34.1356Keywords:
security policies, rule recertification, network firewall, Zero Trust, principle of least privilege, artificial intelligenceAbstract
Modern corporate network infrastructures are characterized by a continuous increase in the number of information services, the widespread use of hybrid and cloud environments, and the growing complexity of network access policies. The dynamic nature of such environments leads to frequent changes in network security configurations, while requirements governing interactions between corporate services may be maintained and updated across different information systems independently of the actual network configuration. As a result, discrepancies may gradually emerge between declared requirements and the network access rights actually granted, making it more difficult to maintain an appropriate level of security and compliance with the principles of Zero Trust Architecture.
This problem is particularly relevant in large corporate environments, where the number of network access rules may reach several thousand, while their periodic analysis and access rights recertification are time-consuming processes that require substantial human and operational resources. Traditional configuration analysis tools can identify certain anomalies; however, they are not always capable of determining the extent to which the access rights actually granted correspond to their original purpose and to the current security requirements of corporate services. This creates conditions for the accumulation of outdated, redundant, undocumented, or overly permissive access rights and complicates the implementation of the principles of least privilege, explicit authorization, and continuous verification of security policies.
This paper investigates the potential use of artificial intelligence technologies to improve the efficiency of network access policy control and recertification processes in the context of implementing Zero Trust principles. A conceptual approach is proposed that focuses on the automated processing of heterogeneous information about corporate services and the actual state of network security policies in order to assess their compliance with security requirements and Zero Trust principles.
The proposed approach involves the use of intelligent configuration analysis to identify potential deviations, detect network access rules that require additional review, and generate recommendations for responsible specialists. In this context, artificial intelligence is considered a supporting mechanism for decision-making rather than an autonomous tool for modifying security policies. The application of this approach is expected to reduce the amount of manual work required during recertification, improve the scalability of the control process, and support the continued alignment of network policies with Zero Trust principles in complex corporate infrastructures.
Downloads
References
Singh, B. P. (2026). Convergence of AI and Zero Trust: Enabling continuous verification across hybrid cloud environments. International Journal of Intelligent Systems and Applications in Engineering, 14(1s), 339–. https://doi.org/10.17762/ijisae.v14i1s.8181
Malik, G. (2022). Implementing Zero Trust Architecture: Modern approaches to secure enterprise networks. International Journal of Networks and Security. https://doi.org/10.55640/ijns-02-01-02
Al-Shaer, E. (2005). Managing network security policies: Firewall and IPSec/VPN. In 2005 9th IFIP/IEEE International Symposium on Integrated Network Management (IM 2005) (p. 787). https://doi.org/10.1109/INM.2005.1440862
Neville, U., & Foley, S. (2016). Reasoning about firewall policies through refinement and composition. Journal of Computer Security, 26, 207–254. https://doi.org/10.3233/JCS-17971
Hu, H., Ahn, G.-J., & Kulkarni, K. (2012). Detecting and resolving firewall policy anomalies. IEEE Transactions on Dependable and Secure Computing, 9, 318–331. https://doi.org/10.1109/TDSC.2012.20
Oluoha, O., Odeshina, A., Reis, O., Okpeke, F., Attipoe, V., & Orieno, O. H. (2024). AI-enabled framework for Zero Trust Architecture and continuous access governance in security-sensitive organizations. International Journal of Social Science Exceptional Research. https://doi.org/10.54660/ijsser.2024.3.1.343-364
García, J., Cuppens-Boulahia, N., & Cuppens, F. (2008). Complete analysis of configuration rules to guarantee reliable network security policies. International Journal of Information Security, 7, 103–122. https://doi.org/10.1007/s10207-007-0045-7
Abubakar, A. (2019). Abstracting network policies. https://doi.org/10.26174/thesis.lboro.10265861.v1
Govaerts, J., Bandara, A., & Curran, K. (2008). A formal logic approach to firewall packet filtering analysis and generation. Artificial Intelligence Review, 29, 223–248. https://doi.org/10.1007/s10462-009-9147-0
García, J., Cuppens, F., & Cuppens-Boulahia, N. (2006). Analysis of policy anomalies on distributed network security setups. In Proceedings (pp. 496–511). https://doi.org/10.1007/11863908_30
Lee, H.-J., Lee, S., Kim, K., & Kim, H. (2024). HSViz-II: Octet layered hierarchy simplified visualizations for distributed firewall policy analysis. IEEE Access, 12, 936–948. https://doi.org/10.1109/ACCESS.2023.3346922
Lee, H., Lee, S., Kim, K., & Kim, H. (2021). HSViz: Hierarchy simplified visualizations for firewall policy analysis. IEEE Access, 9, 71737–71753. https://doi.org/10.1109/ACCESS.2021.3077146
Neville, U., & Foley, S. (2016). Reasoning about firewall policies through refinement and composition. Journal of Computer Security, 26, 207–254. https://doi.org/10.3233/JCS-17971
Reddy, A. R. P. (2025). Zero Trust Architecture: An AI-driven framework for modern cybersecurity challenges. FMDB Transactions on Sustainable Intelligent Networks. https://doi.org/10.69888/ftsin.2025.000366
Oluoha, O., Odeshina, A., Reis, O., Okpeke, F., Attipoe, V., & Orieno, O. H. (2024). AI-enabled framework for Zero Trust Architecture and continuous access governance in security-sensitive organizations. International Journal of Social Science Exceptional Research. https://doi.org/10.54660/ijsser.2024.3.1.343-364
Schulker, D., Wang, J., Mellon, J., & Garrett, R. C. (2025). Behavior-based confidence scoring to support access management in Zero Trust systems. INCOSE International Symposium, 35. https://doi.org/10.1002/iis2.70076
Singh, B. P. (2026). Convergence of AI and Zero Trust: Enabling continuous verification across hybrid cloud environments. International Journal of Intelligent Systems and Applications in Engineering, 14(1s), 339–. https://doi.org/10.17762/ijisae.v14i1s.8181
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Роман Сиротинський, Іван Тишик

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.