System and method for enhancing threat and risk assessment with zero trust access control integration

IN595040BActive Publication Date: 2026-07-10SURYAWANSHI SACHIN +4
0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
IN · IN
Patent Type
Patents
Current Assignee / Owner
SURYAWANSHI SACHIN
Filing Date
2024-12-27
Publication Date
2026-07-10

AI Technical Summary

Technical Problem

Traditional Threat Analysis and Risk Assessment (TARA) frameworks struggle to effectively integrate with Zero Trust Access Control (ZT-AC) principles, particularly in dynamic cloud environments, leading to challenges in continuous risk assessment and access control enforcement.

Method used

Embedding Zero Trust Access Control policies directly into the TARA process to create a comprehensive framework that continuously evaluates and mitigates cybersecurity risks, enforces stringent access controls, and utilizes AI-powered attack tree models for threat simulation and risk scoring.

Benefits of technology

This integration enables robust, real-time risk assessment and access control across modern digital environments, enhancing the security posture of cloud-hosted applications and data by prioritizing risks, mapping threats, and providing actionable recommendations for refining Zero Trust policies.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

Embodiments of the present disclosure relates to a system (100) and method (300) for enhancing Threat and Risk Assessment (TARA) through the integration of Zero Trust Access Control (ZT-AC) principles. The system (100) utilizes a processor (104) to acquire and analyze system assets, define strict access policies based on Zero Trust, and categorize vulnerabilities by their relevance and impact. The system (100) maps threats to assets, incorporates ZT-AC policies to minimize exposure, and develops AI-powered attack tree models to simulate potential attack scenarios. The system (100) validates adherence to Zero Trust principles, simulates mitigating effects within attack trees, and scores risk based on likelihood, impact, and ZT-AC mitigations. Detailed cybersecurity risk assessments are generated, providing actionable recommendations for refining Zero Trust policies and improving overall security.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to the field of cybersecurity. Morespecifically, the present disclosure relates to an enhancement of Threat Analysisand Risk Assessment (TARA) frameworks through the integration of Zero TrustAccess Control (ZT-AC) principles.BACKGROUND

[0002] Background description includes information that may be useful inunderstanding the present disclosure. It is not an admission that any of theinformation provided herein is prior art or relevant to the presently claimeddisclosure, or that any publication specifically or implicitly referenced is prior art.

[0003] The Threat Analysis and Risk Assessment (TARA) methodology hasbeen a cornerstone of cybersecurity for identifying, evaluating, and mitigatingpotential security risks across various systems and infrastructures. TARA allowsorganizations to understand the security posture of their environment bysystematically identifying threats, evaluating risks, and prioritizing mitigationefforts based on the potential impact and likelihood of threats materializing.Traditionally, the approach has been effective in static, on-premise environmentswhere perimeter-based defenses could be relied upon to secure the network.However, the rise of cloud computing, mobile devices, and the proliferation ofremote work have significantly expanded the attack surface and introduced newcomplexities in securing systems.

[0004] In particular, cloud environments present unique challenges thattraditional TARA processes often struggle to address. These environments aredynamic, with resources, applications, and data spread across distributedinfrastructures. Users may access systems from a wide variety of locations, devices,and networks, which complicates the ability to continuously monitor and assesssecurity risks. Furthermore, with the sharing of resources in the cloud, organizationslose some degree of control over the physical infrastructure, making it harder toapply traditional security measures like firewalls or network segmentation. As aresult, cybersecurity threats in cloud environments evolve rapidly, necessitating amore agile and adaptive risk assessment process.

[0005] In response to these challenges, the Zero Trust Security model hasemerged as a promising approach to address the vulnerabilities in modernnetworked systems. The Zero Trust model is based on the principle of "never trust,always verify," which assumes that threats may exist both inside and outside thenetwork. Under this paradigm, no user, device, or application is automaticallytrusted, and all access requests are treated as potentially risky. Access to resourcesis granted based on continuous authentication, authorization, and monitoring, withstrict access controls applied to minimize the attack surface. This model provides astronger defense against data breaches, insider threats, and external attacks byenforcing more granular, context-aware security policies.

[0006] While Zero Trust offers significant benefits, its effectiveimplementation in conjunction with existing risk assessment processes remains achallenge. Traditional TARA frameworks primarily focus on identifying threats,mapping vulnerabilities, and assessing risks, but they do not inherently account forthe continuous, dynamic nature of access controls and the evolving security posturedemanded by Zero Trust principles. The difficulty lies in integrating these twoapproaches to provide a unified, holistic solution that both assesses risks andenforces appropriate access controls across the entire system in real-time.

[0007] To address these limitations, the present disclosure provides a novelsystem and method that overcomes the shortcomings of the prior art.

[0008] The invention addresses the gap by embedding Zero Trust AccessControl (ZT-AC) policies directly into the TARA process. By integrating ZT-ACinto TARA, the invention creates a comprehensive framework that enablesorganizations to continuously evaluate and mitigate cybersecurity risks whileenforcing the stringent access control policies necessary in a zero-trustenvironment. This integration allows for more effective identification andprioritization of risks, mapping of threats to assets, and the construction of attacktree models, all while ensuring that access to critical resources is tightly controlledand continuously verified. By aligning TARA with Zero Trust principles, theinvention provides a robust methodology to secure modern digital environments,including cloud-hosted applications and data, and to safeguard valuableorganizational assets against evolving threats.OBJECTS OF THE PRESENT DISCLOSURE

[0009] Some of the objects of the present disclosure, which at least oneembodiment herein satisfies are as listed herein below.

[0010] It is a primary object of the present disclosure to provide anenhanced Threat Analysis and Risk Assessment (TARA) framework thatincorporates Zero Trust Access Control (ZT-AC) principles to systematicallyidentify, evaluate, and mitigate security risks in modern cybersecurityenvironments, particularly cloud-based systems.

[0011] It is an object of the present disclosure to integrate Zero Trust AccessControl policies with the TARA process in a seamless manner.

[0012] It is another object of the present disclosure to improve theeffectiveness of the TARA methodology by addressing the dynamic and evolvingnature of cybersecurity threats.

[0013] It is yet another object of the present disclosure to enable the securemanagement of cloud-hosted applications and data by providing a robustframework for assessing risks, mapping threats to assets, constructing attack treemodels,

[0014] It is still another object of the present disclosure to create a unifiedcybersecurity methodology that combines risk assessment and access controlenforcement,

[0015] It is still another object of the present disclosure to enable the securemanagement of cloud-hosted applications and data by providing a robustframework for assessing risks, mapping threats to assets, constructing attack treemodels,SUMMARY

[0016] This section is provided to introduce certain objects and aspects ofthe present disclosure in a simplified form that are further described below in thedetailed description. This summary is not intended to identify the key features orthe scope of the claimed subject matter.

[0017] The present disclosure relates to the field of cybersecurity. Morespecifically, the present disclosure relates to an enhancement of Threat Analysis andRisk Assessment (TARA) frameworks through the integration of Zero Trust AccessControl (ZT-AC) principles.

[0018] An aspect of the present disclosure pertains to a system forenhancing Threat and Risk Assessment (TARA) with Zero Trust Access Control(ZT-AC) integration can include a processor and a memory coupled to theprocessor. The memory can contain processor-executable instructions that, whenexecuted, cause the processor to perform a series of tasks. The tasks can includeacquiring and analyzing system assets to establish detailed configurations andaccess requirements, defining strict access policies for the analyzed assets based onZero Trust principles, and collecting and categorizing vulnerabilities by assessingtheir impact on access controls and relevance to the system assets.

[0019] Furthermore, the system can map threats to vulnerabilities and assetsby integrating Zero Trust principles to minimize exposure, develop and customizeAI-powered attack trees to simulate and mitigate potential attack scenarios, andvalidate Zero Trust adherence during risk evaluations while simulating themitigating effects within the attack trees. Furthermore, the system calculates riskscores by factoring in the likelihood, impact, and Zero Trust mitigations, andprovides comprehensive risk assessments along with actionable recommendationsfor continuously improving Zero Trust policies.

[0020] In an aspect, an asset acquisition and analysis module may beconfigured to dynamically update asset records in response to configurationchanges.

[0021] In an aspect, a vulnerability collection and categorization modulemay be configured to employ machine learning algorithms to prioritizevulnerabilities based on exploitation trends.

[0022] In an aspect, a threat mapping module may be configured to utilizegraph-theoretic approaches to establish relationships between any or a combinationof, threats, vulnerabilities, and assets.

[0023] In an aspect, an attack tree model construction module may beconfigured to integrate behavioral analytics to enhance the simulation of potentialattack scenarios.

[0024] In an aspect, an access control enforcement module may beconfigured to perform real-time validation of Zero Trust compliance duringdynamic system operations.

[0025] In an aspect, a risk scoring and evaluation module may beconfigured to apply weighted algorithms to score attack trees based on the directand indirect effects of ZT-AC mitigations on threat likelihood and impact.

[0026] In an aspect, the comprehensive risk assessments may be configuredto generate by the system including recommendations for deploying adaptive ZT-AC policies based on evolving threat landscapes.

[0027] An aspect of the present disclosure pertains to a method forenhancing Threat and Risk Assessment (TARA) with Zero Trust Access Control(ZT-AC) integration can include several steps. First, the processor can identify andacquire system assets as a basis for comprehensive analysis. It then analyzes thedetailed asset configurations and access requirements to inform policy definitions.The processor can define strict access policies for each asset based on Zero Trustprinciples, enforcing least privilege and "need-to-know" criteria. Next, it collectsand categorizes vulnerabilities based on their relevance to the system assets andtheir impact on access controls.

[0028] Furthermore, the processor can map identified threats tovulnerabilities and system assets while incorporating ZT-AC policies to restrictexposure pathways. It establishes and utilizes relationships between threat types,threat scenes, and asset information within the context of zero-trust principles. Theprocessor can construct and adapt AI-powered attack tree models to simulate andanalyze potential attack scenarios with integrated zero-trust measures. The methodthen can validate strict adherence to Zero Trust principles before risk evaluation andsimulate the effectiveness of ZT-AC policies within the modeled attack trees toquantify and mitigate impacts. It scores the attack trees based on likelihood, impact,and ZT-AC mitigations. Finally, the processor can generate detailed cybersecurityrisk assessments and provide actionable recommendations for refining Zero Trustpolicies.BRIEF DESCRIPTION OF DRAWINGS

[0029] The accompanying drawings are included to provide a furtherunderstanding of the present disclosure, and are incorporated in, and constitute apart of this specification. The drawings illustrate exemplary embodiments of thepresent disclosure, and together with the description, serve to explain the principlesof the present disclosure.

[0030] In the figures, similar components, and / or features may have thesame reference label. Further, various components of the same type may bedistinguished by following the reference label with a second label that distinguishesamong the similar components. If only the first reference label is used in thespecification, the description is applicable to any one of the similar componentshaving the same first reference label irrespective of the second reference label.

[0031] FIG. 1 illustrates an exemplary representation of architecture of theproposed system for enhancing Threat and Risk Assessment (TARA) with ZeroTrust Access Control (ZT-AC) integration, in accordance with an embodiment ofthe present disclosure.

[0032] FIG. 2 illustrates a module diagram representation of the proposedsystem for enhancing Threat and Risk Assessment (TARA) with Zero Trust AccessControl (ZT-AC) integration, in accordance with an embodiment of the presentdisclosure.

[0033] FIG. 3 illustrates an exemplary view of a flow diagram of theproposed method enhancing Threat and Risk Assessment (TARA) with Zero TrustAccess Control (ZT-AC) integration, in accordance with an embodiment of thepresent disclosure.DETAILED DESCRIPTION

[0034] The following is a detailed description of embodiments of thedisclosure depicted in the accompanying drawings. The embodiments are in suchdetail as to clearly communicate the disclosure. However, the amount of detailoffered is not intended to limit the anticipated variations of embodiments. On thecontrary, the intention is to cover all modifications, equivalents, and alternativesfalling within the spirit, and scope of the present disclosure as defined by theappended claims.

[0035] In the following description, numerous specific details are set forthin order to provide a thorough understanding of embodiments of the presentinvention. It will be apparent to one skilled in the art that embodiments of thepresent invention may be practiced without some of these specific details.

[0036] Specific details are given in the following description to provide athorough understanding of the embodiments. However, it will be understood by oneof ordinary skill in the art that the embodiments may be practiced without thesespecific details. For example, circuits, systems, networks, processes, and othercomponents may be shown as components in block diagram form in order not toobscure the embodiments in unnecessary detail. In other instances, well-knowncircuits, processes, algorithms, structures, and techniques may be shown withoutunnecessary detail to avoid obscuring the embodiments.

[0037] The present disclosure relates to the field of cybersecurity. Morespecifically, the present disclosure relates to an enhancement of Threat Analysis andRisk Assessment (TARA) frameworks through the integration of Zero Trust AccessControl (ZT-AC) principles.

[0038] FIG. 1 illustrates an exemplary architecture of the proposed systemfor crowdsourced cybersecurity threat identification and management, inaccordance with an embodiment of the present disclosure.

[0039] Illustrated in FIG. 1 is an architecture representation of the system100 for enhancing Threat and Risk Assessment (TARA) with Zero Trust AccessControl (ZT-AC) integration. The system 100 is connected to a network 110, oneor more computing devices (108-1, 108-2,…,108-N) (individually referred to asone or more computing devices 108), and a centralized server 102. The system 100includes a processor 104 and a memory 106. The memory 106 may include a set ofinstructions, which when executed, causes the processor 104 to enhance Threat andRisk Assessment (TARA) with Zero Trust Access Control (ZT-AC) integration.

[0040] In an embodiment, the system 100 for enhancing Threat and RiskAssessment (TARA) with Zero Trust Access Control (ZT-AC) integration caninclude the processor 104 and the memory 106, where the memory 106 storesexecutable instructions that, when executed, cause the processor to perform varioustasks. The tasks can involve acquiring and analysing system assets, defining strictaccess policies based on Zero Trust principles, categorizing vulnerabilities basedon their relevance and impact on access controls, and mapping threats to assetswhile minimizing exposure. The system 100 can also develop AI-powered attacktrees to simulate and mitigate attack scenarios, validate adherence to Zero Trustduring risk evaluations, and calculate risk scores based on the likelihood, impact,and effectiveness of Zero Trust mitigations. Finally, the system 100 can providecomprehensive risk assessments and actionable recommendations for continuouslyimproving Zero Trust policies.

[0041] FIG. 2 illustrates a module diagram representation of the proposedsystem for enhancing Threat and Risk Assessment (TARA) with Zero Trust AccessControl (ZT-AC) integration, in accordance with an embodiment of the presentdisclosure.

[0042] Illustrated in FIG. 2 is a module diagram 200 of the system 100enhancing Threat and Risk Assessment (TARA) with Zero Trust Access Control(ZT-AC) integration. The system 102 can include one or more processor(s) 104.The one or more processor(s) 104 may be implemented as one or moremicroprocessors, microcomputers, microcontrollers, digital signal processors,central processing units, logic circuitries, and / or any devices that manipulate databased on operational instructions. Among other capabilities, one or moreprocessor(s) 104 are configured to fetch and execute computer-readable instructionsstored in a memory 106. The memory 106 can store one or more computer-readableinstructions or routines, which are fetched and executed to execute a sequence oftasks to facilitate crowdsourced cybersecurity threat identification andmanagement.

[0043] In an embodiment, the module diagram 200 can include aninterface(s) 208. The interface(s) 208 may include a variety of interfaces, forexample, interfaces for data input and output devices, referred to as I / O devices,storage devices, and the like. The interface(s) 208 can facilitate communicationto / from the system 100. The interface(s) 208 may also provide a communicationpathway for one or more components of the system 100. Examples of suchcomponents include but are not limited to, processing unit / engine(s) 210 and adatabase 202.

[0044] In an embodiment, the processing unit / engine(s) 210 may beimplemented as a combination of hardware and programming (for example,programmable instructions) to implement one or more functionalities of theprocessing engine(s) 210. In the examples described herein, such combinations ofhardware and programming may be implemented in several different ways. Forexample, the programming for the processing engine(s) 210 may be processor-executable instructions stored on a non-transitory machine-readable storagemedium and the hardware for the processing engine(s) 210 may include aprocessing resource (for example, one or more processors), to execute suchinstructions.

[0045] In the present examples, the machine-readable storage medium maystore instructions that, when executed by the processing resource, implement theprocessing engine(s) 210. In such examples, the system 100 may include themachine-readable storage medium storing the instructions and the processingresource to execute the instructions, or the machine-readable storage medium maybe separate but accessible to the system 100 and the processing resource. In otherexamples, the processing engine(s) 210 may be implemented by electronic circuitry.

[0046] In an embodiment, the database 202 may include data that may beeither stored or generated as a result of functionalities implemented by any of thecomponents of the processor 104 or the processing engine 210. In an embodiment,the database 202 may be separate from the system 100.

[0047] In an exemplary embodiment, the processing engine 210 mayinclude one or more engines selected from any of comprises an asset acquisitionand analysis module 212, a vulnerability collection and categorization module 214,a threat mapping module 216, an attack tree model construction module 218, a riskscoring and evaluation module 220, and a risk scoring and evaluation module 222.

[0048] In an embodiment, the asset acquisition and analysis module 212involves identifying and acquiring system assets, followed by analyzing the assetinformation, including configurations and access requirements. Based on themodule 212, strict access policies are defined for each asset, guided by Zero Trustprinciples. These policies can enforce the least privilege and "need-to-know"criteria, ensuring that access is granted only to authorized users and devices withthe minimum necessary permissions.

[0049] In an embodiment, the vulnerability collection and categorization214 can involve gathering known vulnerabilities from public libraries and othersources. These vulnerabilities may be then categorized based on their relevance tothe system assets and their potential impact on access controls. The process helpsprioritize which vulnerabilities need to be addressed based on their potential toaffect the security of critical system components.

[0050] In an embodiment, the threat mapping module 216 can involvemapping threats to assets with ZT-AC Integration linking identified threats to thesystem vulnerabilities and assets. Zero Trust Access Control (ZT-AC) policies maybe incorporated into the mapping process to minimize exposure by enforcing strictaccess restrictions. Furthermore, relationships may be established between differentthreat types, threat scenarios, and asset information, all within the context of ZeroTrust principles, ensuring that access is continuously verified and controlled toreduce risk.

[0051] In an embodiment, the attack tree model construction module 218can include attack tree model construction with access control considerationsinvolves developing an AI-powered library of attack tree models to simulatepotential attack scenarios. The attack trees are tailored to target specific systems byintegrating Zero Trust Access Control (ZT-AC) principles. The integration can helpidentify and mitigate potential attack paths by ensuring that access to critical assetsis tightly controlled and continuously verified, reducing the likelihood of successfulbreaches.

[0052] In an embodiment, the access control enforcement module 220 caninclude enforcing zero trust access control involves validating strict adherence toZero Trust principles before conducting risk evaluations. This can ensure that allaccess requests are verified and authorized based on Zero Trust policies.Furthermore, the mitigating effects of these ZT-AC policies are simulated withinattack trees to assess their impact on potential attack scenarios, helping to determinehow effectively access controls can prevent or minimize threats.

[0053] In an embodiment, the risk scoring and evaluation module 222 caninclude scoring the attack trees based on factors such as the likelihood of an attack,its potential impact, and the effectiveness of Zero Trust Access Control (ZT-AC)mitigations. The process results in detailed cybersecurity risk assessments, whichprovide insights into the security posture of the system. Additionally, actionablerecommendations are generated to refine Zero Trust policies, ensuring continuousimprovement in safeguarding against potential threats.

[0054] FIG. 3 illustrates an exemplary view of a flow diagram of theproposed method enhancing Threat and Risk Assessment (TARA) with Zero TrustAccess Control (ZT-AC) integration, in accordance with an embodiment of thepresent disclosure.

[0055] As illustrated in FIG. 3, a method 300 proposes an enhancing Threatand Risk Assessment (TARA) with Zero Trust Access Control (ZT-AC) integration.At step 302, the method 300 may involve identifying and acquiring, by a processor104, system assets, where the system assets may be recognized and collected as thefoundational data set for conducting a thorough and detailed analysis of thesystem's security configuration, functionalities, and access requirements.

[0056] Continuing further, at step 304, the method 300 may involveanalyzing, by the processor 104, detailed configurations and access requirements ofthe identified system assets, where the processor 104 can evaluate the assetcharacteristics, including but not limited to, hardware specifications, softwaresettings, and user access privileges, to generate informed policy definitions thatgovern the management and control of access to the system assets based on securityrequirements.

[0057] Continuing further, at step 306, the method 300 may involvedefining, by the processor 104, strict access policies for each identified system assetbased on Zero Trust principles, where the processor 104 can establish accesscontrols that enforce the least privilege and "need-to-know" criteria, such thataccess to each asset is granted only to authorized users or entities with the minimumnecessary permissions required for performing their specific tasks, ensuring that allaccess requests are continuously verified and validated before being granted.

[0058] Continuing further, at step 308, the method 300 may involvecollecting and categorizing, by the processor 104, vulnerabilities present within thesystem 100, where the processor 104 can identify and comply vulnerabilities fromrelevant sources and categorize them based on their significance to the systemassets and their potential impact on access controls, thereby enabling theprioritization of vulnerabilities that pose the highest risk to the security and integrityof the system's access management framework.

[0059] Continuing further, at step 310, the method 300 may involvemapping, by the processor 104, identified threats to corresponding vulnerabilitiesand system assets, where the processor 104 can integrate Zero Trust Access Control(ZT-AC) policies to establish restricted exposure pathways, thereby enabling theidentification of threat-vulnerability-asset relationships and facilitating thedevelopment of targeted security measures to minimize exposure and reduce thepotential impact of security breaches.

[0060] Continuing further, at step 312, the method 300 may involveestablishing and utilizing, by the processor 104, relationships between differentthreat types, threat scenarios, and asset information, where the processor 104 cananalyze and correlate various threat vectors and contexts with the correspondingsystem assets, all within the framework of Zero Trust principles, to ensure that allaccess to assets is continuously verified and that the security posture accounts forboth internal and external threat scenarios.

[0061] Continuing further, at step 314, the method 300 may involveconstructing and adapting, by the processor 104, AI-powered attack tree models,where the processor 104 can generate and customize attack tree models usingartificial intelligence techniques to simulate and analyze potential attack scenarios,with integrated Zero Trust measures, such that the attack paths are evaluated basedon Zero Trust principles, including continuous verification of access requests,minimization of exposure, and enforcement of strict access controls, to assess andmitigate security risks associated with each scenario.

[0062] Continuing further, at step 316, the method 300 may involvevalidating, by the processor 104, strict adherence to Zero Trust principles prior toperforming a risk evaluation, where the processor 104 can ensure that all accesscontrol policies, security configurations, and user authentication processes complywith Zero Trust guidelines, such that no access is granted without continuousverification, and all trust assumptions are eliminated, thereby guaranteeing that onlyauthorized entities are permitted access before conducting any risk assessment orevaluation.

[0063] Continuing further, at step 318, the method 300 may involvesimulating, by the processor 104, the effectiveness of Zero Trust Access Control(ZT-AC) policies within modeled attack trees, where the processor 104 can executesimulations to assess the impact of ZT-AC policies on identified attack scenarios,and quantifies the mitigate effects of these policies by evaluating their ability toprevent or reduce the success of potential attacks, thereby providing insights intothe effectiveness of access controls and security measures in real-world threatenvironments.

[0064] Continuing further, at step 320, the method 300 may involve scoring,by the processor 104, the attack trees based on likelihood, impact, and Zero TrustAccess Control (ZT-AC) mitigations, where the processor 104 can evaluate eachattack scenario in the tree by assigning scores based on the probability of occurrence(likelihood), the potential consequences or damage (impact), and the effectivenessof ZT-AC policies in mitigating the risk, thereby providing a comprehensiveassessment of the threat level and the efficacy of the applied security measures.

[0065] Continuing further, at step 322, the method 300 may involvegenerating, by the processor 104, detailed cybersecurity risk assessments, where theprocessor 104 can comply and analyses data from the attack trees, vulnerabilityassessments, and the effectiveness of Zero Trust Access Control (ZT-AC) policiesto produce comprehensive evaluations of the system's security posture.Furthermore, the processor 104 can provide actionable recommendations forrefining and enhancing Zero Trust policies, aimed at improving the overall securityframework and mitigating identified risks, based on the insights gained from therisk assessments.

[0066] In summary, the present disclosure outlines a system and method forenhancing Threat and Risk Assessment (TARA) through the integration of ZeroTrust Access Control (ZT-AC) principles. The system, powered by a processor,acquires and analyzes system assets, defines strict access policies based on ZeroTrust principles, and categorizes vulnerabilities based on their relevance andimpact. It maps threats to vulnerabilities and assets, utilizes AI-powered attack treemodels to simulate and assess potential attack scenarios, and validates adherence toZero Trust policies. By scoring attack trees based on likelihood, impact, and ZT-AC mitigations, the system generates detailed cybersecurity risk assessments andprovides actionable recommendations to refine and strengthen Zero Trust policies,ensuring continuous improvement in the security framework.

[0067] While the foregoing describes various embodiments of theinvention, other and further embodiments of the invention may be devised withoutdeparting from the basic scope thereof. The scope of the invention is determined bythe claims that follow. The invention is not limited to the described embodiments,versions or examples, which are comprised to enable a person having ordinary skillin the art to make and use the invention when combined with information andknowledge available to the person having ordinary skill in the art.ADVANTAGES OF THE INVENTION

[0068] The present disclosure provides a system to integrate Zero TrustAccess Control (ZT-AC) principles to proactively minimize vulnerabilities andreduce attack surfaces, enhancing the security posture of the system.

[0069] The present disclosure provides a system to utilize AI-driven attacktree models to simulate and analyze a wide range of potential threats, enablingdynamic and real-time threat modeling for effective risk management.

[0070] The present disclosure provides a system to combine likelihood,impact, and mitigation factors to deliver precise and holistic risk assessments,ensuring a thorough understanding of security risks and their potentialconsequences.

[0071] The present disclosure provides a system to deliver actionableinsights and recommendations for refining and strengthening Zero Trustimplementations, ensuring continuous improvement of access control policies andoverall security measures.

[0072] The present disclosure provides a system enables informed decision-making for prioritizing security measures and allocating resources effectively.

[0073] The present disclosure provides a system to reduce the attack surfaceby ensuring that only authorized users and devices have access to critical systemassets.

Claims

1. A system (100) for enhancing Threat and Risk Assessment (TARA) with Zero Trust Access Control (ZT-AC) integration, comprising: a processor (104); and a memory (106) coupled to the processor (104), wherein the memory (106) comprises processor-executable instructions, which on execution, causes the processor (104) to: acquire and analyze system assets to establish detailed configurations and access requirements; define strict access policies for analyzed assets based on Zero Trust principles; collect and categorize vulnerabilities by assessing their impact on access controls and relevance to the system assets; map threats to vulnerabilities and assets by integrating Zero Trust principles to minimize exposure; develop and customize AI-powered attack trees that simulate and mitigate potential attack scenarios; validate Zero Trust adherence during risk evaluations and simulate the mitigating effects within the attack trees; calculate risk scores by factoring in the likelihood, impact, and Zero Trust mitigations; and provide comprehensive risk assessments and actionable recommendations for continuously improving Zero Trust policies.

2. The system (100) as claimed in claim 1, further comprises an asset acquisition and analysis module (212) configured to dynamically update asset records in response to configuration changes.

3. The system (100) as claimed in claim 1, further comprises a vulnerability collection and categorization module (214) configured to employ machine learning algorithms to prioritize vulnerabilities based on exploitation trends.

4. The system (100) as claimed in claim 1, further comprises a threat mapping module (216) configured to utilize graph-theoretic approaches to establish relationships between any or a combination of, threats, vulnerabilities, and assets.

5. The system (100) as claimed in claim 1, further comprises an attack tree model construction module (218) configured to integrate behavioral analytics to enhance the simulation of potential attack scenarios.

6. The system (100) as claimed in claim 1, further comprises an access control enforcement module (220) configured to perform real-time validation of Zero Trust compliance during dynamic system operations.

7. The system (100) as claimed in claim 1, further comprises a risk scoring and evaluation module (222) configured to apply weighted algorithms to score attack trees based on direct and indirect effects of ZT-AC mitigations on threat likelihood and impact.

8. The system (100) as claimed in claim 1, wherein the comprehensive risk assessments configured to generate by the system (100) include recommendations for deploying adaptive ZT-AC policies based on evolving threat landscapes.

9. A method (300) for enhancing Threat and Risk Assessment (TARA) with Zero Trust Access Control (ZT-AC) integration, the method (300) comprises steps of: identifying and acquiring (302), by a processor (104), system assets as a basis for comprehensive analysis; analysing (304), by the processor (104), detailed asset configurations and access requirements to inform policy definitions; defining (306), by the processor (104), strict access policies for each asset based on Zero Trust principles, enforcing least privilege and "need-toknow" criteria; collecting and categorizing (308), by the processor (104), vulnerabilities based on their relevance to system assets and their impact on access controls; mapping (310), by the processor (104), identified threats to vulnerabilities and the system assets while incorporating ZT-AC policies to restrict exposure pathways; establishing and utilizing (312), by the processor (104), relationships between threat types, threat scenes, and asset information within the context of Zero Trust principles; constructing and adapting (314), by the processor (104), AI-powered attack tree models to simulate and analyze potential attack scenarios with integrated Zero Trust measures; validating (316), by the processor (104), strict adherence to Zero Trust principles before risk evaluation; simulating (318), by the processor (104), the effectiveness of ZT-AC policies within modeled attack trees to quantify mitigate impacts; scoring (320), by the processor (104), the attack trees based on likelihood, impact, and ZT-AC mitigations; and generating (322), by the processor (104), detailed cybersecurity risk assessments and providing actionable recommendations for refining Zero Trust policies.