EXPERIMENTAL STUDY OF AN ADAPTIVE CONTEXTUAL ACCESS CONTROL MODEL FOR ENHANCING THE RESILIENCE OF CRITICAL INFORMATION SYSTEMS
DOI:
https://doi.org/10.28925/2663-4023.2026.34.1364Keywords:
critical information systems, critical infrastructure, contextual access control, adaptive model, Zero Trust, risk assessment, cybersecurity, resilienceAbstract
In the context of the growing number and increasing complexity of cyber threats, ensuring secure access to critical information systems (CIS) is one of the key tasks in protecting the state’s critical information infrastructure. The use of adaptive access control mechanisms capable of accounting for changes in endpoint device posture, user privilege levels, and access environment parameters in accordance with the principles of the Zero Trust architecture is becoming increasingly important. This article presents an experimental study of an adaptive contextual access control model aimed at enhancing the resilience of CIS. To conduct the experiment, the model parameters were specified taking into account the characteristics of energy-sector CIS, a set of access scenarios was formed, and a software-based evaluation of the proposed approach was performed in comparison with existing access control models. The experimental results confirmed the adequacy and operability of the proposed model, as well as its ability to adaptively make access decisions in response to changes in contextual parameters. For scenarios related to endpoint device posture, the model demonstrated the highest average accuracy among the approaches considered, reaching 0.742, while under the reference policy prioritizing endpoint device posture, its accuracy reached 0.756. The results confirmed the feasibility of applying the proposed model to CIS in which endpoint device posture is one of the priority risk factors. The practical significance of the obtained results lies in the possibility of applying the developed model to build adaptive contextual access control systems for CIS while taking into account the threat profile of a specific critical information infrastructure facility. Further research will focus on improving the method for aggregating contextual parameters, expanding the set of experimental scenarios, and validating the proposed model using real-world CIS data.
Downloads
References
Verkhovna Rada of Ukraine. (2021). On critical infrastructure: Law of Ukraine No. 1882-IX. https://zakon.rada.gov.ua/laws/show/1882-20
Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero Trust architecture (NIST SP 800-207). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-207
Cybersecurity and Infrastructure Security Agency. (2023). Zero Trust maturity model (Version 2.0). U.S. Department of Homeland Security. https://www.cisa.gov/zero-trust-maturity-model
Cloud Security Alliance. (2024). Zero Trust guidance for critical infrastructure. https://cloudsecurityalliance.org/
European Parliament and Council. (2022). Directive (EU) 2022/2555 (NIS2). Official Journal of the European Union. https://eur-lex.europa.eu/eli/dir/2022/2555/oj
European Union Agency for Cybersecurity. (2024). ENISA threat landscape 2024. https://www.enisa.europa.eu/publications/enisa-threat-landscape-2024
Verizon. (2025). 2025 data breach investigations report. Verizon Business. https://www.verizon.com/business/resources/reports/dbir/
Computer Emergency Response Team of Ukraine. (2024). UAC-0133 (Sandworm) plans for cyber sabotage at almost 20 critical infrastructure facilities in Ukraine [Advisory]. CERT-UA. https://cert.gov.ua/article/6278706
Sydorenko, V. M., & Kobilnyk, B. Yu. (2025). Adaptive contextual access control model for enhancing the resilience of critical information systems. Cybersecurity: Education, Science, Technique, 3(31). https://doi.org/10.28925/2663-4023.2025.31.1084
Sydorenko, V. M., & Maksymets, A. V. (2025). Model for ensuring the resilience of critical information systems under the influence of internal and external destabilizing factors. Cybersecurity: Education, Science, Technique, 3(27). https://doi.org/10.28925/2663-4023.2025.27.779
Jeong, E., & Yang, D. (2025). A trust score-based access control model for Zero Trust architecture: Design, sensitivity analysis, and real-world performance evaluation. Applied Sciences, 15(17), 9551. https://doi.org/10.3390/app15179551
Bradatsch, L., Miroshkin, O., Trkulja, N., & Kargl, F. (2023). Zero Trust score-based network-level access control in enterprise networks. Proceedings of the 22nd IEEE TrustCom, 1422–1429. https://doi.org/10.1109/TrustCom60117.2023.00194
Wang, J., Wang, Z., Song, J., Cheng, H., Cao, Y., & Li, Z. (2023). Attribute and user trust score-based Zero Trust access control model in IoV. Electronics, 12(23), 4825. https://doi.org/10.3390/electronics12234825
Lukaseder, T., Halter, M., & Kargl, F. (2020). Context-based access control and trust scores in Zero Trust campus networks. In Sicherheit 2020, LNI (pp. 53–66). Gesellschaft für Informatik. https://doi.org/10.18420/sicherheit2020_04
Gambo, M. L., & Almulhem, A. (2025). Zero Trust architecture: A systematic literature review. Journal of Network and Systems Management, 33. https://doi.org/10.1007/s10922-025-09998-x
Zohaib, S. M., Sajjad, S. M., Iqbal, Z., Yousaf, M., Haseeb, M., & Muhammad, Z. (2024). Zero Trust VPN (ZT-VPN): A systematic literature review and cybersecurity framework for hybrid and remote work. Information, 15(11), 734. https://doi.org/10.3390/info15110734
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Богдан Кобільник, Вікторія Сидоренок

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.