Jul 2026· Journal of Intelligent Decision Making and Information Science· Vol 3, pp. 1559-1582· 0 citations· 25 references
TL;DR
A new control approach for PAM known as the Zero-Trust Control Framework, based on behavioural analysis, graph theory, and entropy calculations is proposed, based on behavioural analysis, graph theory, and entropy calculations for enhancing zero trust enforcement in z/OS administration.
Abstract
The PAM in z/OS systems needs additional measures in the realm of protecting sensitive data from misuse by insiders and credential abuse. Classic approaches using authentication through static mechanisms do not provide adequate protection of administrative sessions that use RACF, TSO, and SDSF, thus leaving systems open to risks associated with administrative activities. To combat these risks, this paper proposes implementing a new control approach for PAM known as the Zero-Trust Control Framework, based on behavioural analysis, graph theory, and entropy calculations. The new tool developed as part of this framework is called Behavioural Identity Drift Analyzer (BIDA). As such, the Privilege Interaction Graph Transformer (PIGT) leverages graph neural networks and transformers to generate privilege interaction graphs that detect the escalation routes, dependencies, and propagation vectors of insider threats in near real-time. Lastly, the Entropy Adaptive Zero-Trust Orchestrator (EAZTO) analyzes uncertainties in user actions, commands, and privileges in order to apply adaptive control measures such as multi-factor authentication, privilege reduction, or even session termination. In combination, these four modules provide layers of protection and achieve continuous PAM decision-making at 90 percent accuracy for the purpose of enhancing zero trust enforcement in z/OS administration.
This study designed and empirically validated a three-layer Zero Trust architecture for Microsoft SQL Server that natively integrates instance-level authentication governance, enhanced Role-Based Access Control with Row-Level Security and Just-in-Time privilege elevation, and metadata-driven Attribute-Based Access Cont...
Maynard Capil, D. Dasig· JPAIR Multidisciplinary Rese...· 0 citations
This architecture provides a systematic foundation for the three core Zero Trust behaviors while eliminating, for participating mechanisms that use the coordinated namespace, the class of cross-namespace correspondence dependencies the authors call identifier glue.
The findings show that kernel-level data-transport and synchronization choices directly influence the classes of concurrency and memory-sharing defects exposed by each TEE architecture.
The increasing number of vulnerabilities in operating systems, together with sophisticated kernel-level threats (e.g., rootkits), has weakened the effectiveness of traditional in-kernel protection mechanisms. Since these defenses operate at the same privilege level as the kernel, they share the same attack surface and...
Zhen-Ling Duan, Pan Dong, Renshuang Jiang et al.· 0 citations
LLM agents translate natural-language context, which may include attacker-controlled text, into privileged tool calls, so authorization must remain effective even when an agent is prompt-injected or adversarially steered. The Model Context Protocol (MCP) has become a widely adopted interface for this boundary, yet its...
The software-as-a-service model places most technical security mechanisms in the provider's hands, while the customer remains accountable for data, identities, and regulatory outcomes. Certification reports describe what a provider has implemented, yet reveal little about what a tenant can monitor and verify on its own...
Sergei Beliachkov· International Journal of Mod...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.