EXPERIMENTAL STUDY OF AN ADAPTIVE CONTEXTUAL ACCESS CONTROL MODEL FOR ENHANCING THE RESILIENCE OF CRITICAL INFORMATION SYSTEMS

Authors

DOI:

https://doi.org/10.28925/2663-4023.2026.34.1364

Keywords:

critical information systems, critical infrastructure, contextual access control, adaptive model, Zero Trust, risk assessment, cybersecurity, resilience

Abstract

In the context of the growing number and increasing complexity of cyber threats, ensuring secure access to critical information systems (CIS) is one of the key tasks in protecting the state’s critical information infrastructure. The use of adaptive access control mechanisms capable of accounting for changes in endpoint device posture, user privilege levels, and access environment parameters in accordance with the principles of the Zero Trust architecture is becoming increasingly important. This article presents an experimental study of an adaptive contextual access control model aimed at enhancing the resilience of CIS. To conduct the experiment, the model parameters were specified taking into account the characteristics of energy-sector CIS, a set of access scenarios was formed, and a software-based evaluation of the proposed approach was performed in comparison with existing access control models. The experimental results confirmed the adequacy and operability of the proposed model, as well as its ability to adaptively make access decisions in response to changes in contextual parameters. For scenarios related to endpoint device posture, the model demonstrated the highest average accuracy among the approaches considered, reaching 0.742, while under the reference policy prioritizing endpoint device posture, its accuracy reached 0.756. The results confirmed the feasibility of applying the proposed model to CIS in which endpoint device posture is one of the priority risk factors. The practical significance of the obtained results lies in the possibility of applying the developed model to build adaptive contextual access control systems for CIS while taking into account the threat profile of a specific critical information infrastructure facility. Further research will focus on improving the method for aggregating contextual parameters, expanding the set of experimental scenarios, and validating the proposed model using real-world CIS data.

Downloads

Download data is not yet available.

References

Verkhovna Rada of Ukraine. (2021). On critical infrastructure: Law of Ukraine No. 1882-IX. https://zakon.rada.gov.ua/laws/show/1882-20

Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero Trust architecture (NIST SP 800-207). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-207

Cybersecurity and Infrastructure Security Agency. (2023). Zero Trust maturity model (Version 2.0). U.S. Department of Homeland Security. https://www.cisa.gov/zero-trust-maturity-model

Cloud Security Alliance. (2024). Zero Trust guidance for critical infrastructure. https://cloudsecurityalliance.org/

European Parliament and Council. (2022). Directive (EU) 2022/2555 (NIS2). Official Journal of the European Union. https://eur-lex.europa.eu/eli/dir/2022/2555/oj

European Union Agency for Cybersecurity. (2024). ENISA threat landscape 2024. https://www.enisa.europa.eu/publications/enisa-threat-landscape-2024

Verizon. (2025). 2025 data breach investigations report. Verizon Business. https://www.verizon.com/business/resources/reports/dbir/

Computer Emergency Response Team of Ukraine. (2024). UAC-0133 (Sandworm) plans for cyber sabotage at almost 20 critical infrastructure facilities in Ukraine [Advisory]. CERT-UA. https://cert.gov.ua/article/6278706

Sydorenko, V. M., & Kobilnyk, B. Yu. (2025). Adaptive contextual access control model for enhancing the resilience of critical information systems. Cybersecurity: Education, Science, Technique, 3(31). https://doi.org/10.28925/2663-4023.2025.31.1084

Sydorenko, V. M., & Maksymets, A. V. (2025). Model for ensuring the resilience of critical information systems under the influence of internal and external destabilizing factors. Cybersecurity: Education, Science, Technique, 3(27). https://doi.org/10.28925/2663-4023.2025.27.779

Jeong, E., & Yang, D. (2025). A trust score-based access control model for Zero Trust architecture: Design, sensitivity analysis, and real-world performance evaluation. Applied Sciences, 15(17), 9551. https://doi.org/10.3390/app15179551

Bradatsch, L., Miroshkin, O., Trkulja, N., & Kargl, F. (2023). Zero Trust score-based network-level access control in enterprise networks. Proceedings of the 22nd IEEE TrustCom, 1422–1429. https://doi.org/10.1109/TrustCom60117.2023.00194

Wang, J., Wang, Z., Song, J., Cheng, H., Cao, Y., & Li, Z. (2023). Attribute and user trust score-based Zero Trust access control model in IoV. Electronics, 12(23), 4825. https://doi.org/10.3390/electronics12234825

Lukaseder, T., Halter, M., & Kargl, F. (2020). Context-based access control and trust scores in Zero Trust campus networks. In Sicherheit 2020, LNI (pp. 53–66). Gesellschaft für Informatik. https://doi.org/10.18420/sicherheit2020_04

Gambo, M. L., & Almulhem, A. (2025). Zero Trust architecture: A systematic literature review. Journal of Network and Systems Management, 33. https://doi.org/10.1007/s10922-025-09998-x

Zohaib, S. M., Sajjad, S. M., Iqbal, Z., Yousaf, M., Haseeb, M., & Muhammad, Z. (2024). Zero Trust VPN (ZT-VPN): A systematic literature review and cybersecurity framework for hybrid and remote work. Information, 15(11), 734. https://doi.org/10.3390/info15110734

Downloads


Abstract views: 10

Published

2026-09-24

How to Cite

Kobilnyk, B., & Sydorenko, V. (2026). EXPERIMENTAL STUDY OF AN ADAPTIVE CONTEXTUAL ACCESS CONTROL MODEL FOR ENHANCING THE RESILIENCE OF CRITICAL INFORMATION SYSTEMS. Electronic Professional Scientific Journal «Cybersecurity: Education, Science, Technique», 2(34), 702–718. https://doi.org/10.28925/2663-4023.2026.34.1364

Most read articles by the same author(s)