Return
Adaptive Policy-Oriented Cybersecurity: A Decentralized Framework Using Message Passing Algorithms for Dynamic Threat Mitigation
DOI:10.1109/ACCESS.2025.3559428.png)
Abstract
En 中文
In the face of increasingly sophisticated and dynamic cyber threats, policy-based cybersecurity deployment has emerged as a critical strategy for securing modern, complex network infrastructures. This approach enables organizations to enforce adaptable, scalable and context-aware security policies that can dynamically respond to evolving threats and operational demands. However, the growing complexity of distributed systems and the interdependencies between diverse security components present significant challenges in ensuring consistent and efficient policy enforcement. Static and centralized security models are no longer sufficient to address these challenges, underscoring the need for intelligent, distributed solutions that can optimize policy deployment in real-time. This paper introduces a novel framework based on Message Passing algorithms that enables decentralized, adapted and optimized policy deployment across complex cybersecurity infrastructures. More specifically, we extend the traditional Min-Sum algorithm by incorporating dynamic trust weights that influence policy enforcement decisions, allowing more reliable nodes to have a greater impact while mitigating the risks posed by untrusted entities. The proposed framework is designed to handle large-scale network environments with minimal computational overhead, relying on localized message exchanges instead of centralized computations. We benchmark our framework against state-of-the-art approaches, demonstrating that the proposed framework achieves lower total enforcement cost while significantly improving convergence speed, particularly in heterogeneous trust environments. Finally, we provide an in-depth evaluation of how trust heterogeneity influences security policy enforcement. Extensive simulations were conducted to evaluate the framework's effectiveness in optimizing policy deployment for varying network topologies, demonstrating significant improvements in threat detection accuracy, policy consistency and resource efficiency across diverse and dynamic network environments.
Keywords:
Security
Computer security
Heuristic algorithms
Costs
Adaptation models
Message passing
Complexity theory
Computational modeling
Reliability
Adaptive systems
Adaptive cybersecurity
policy-based security
message passing algorithms
threat detection
decentralized decision-making
Journal
IF:
3.6
Papers:
9.8W
Citations:
29.4W

