A Risk-Aware Digital Twin Framework for Release-Readiness Validation of Multi-Tenant Zero Trust SASE Systems
DOI:
https://doi.org/10.62051/f19vvd53Keywords:
Digital twin; Release readiness; SASE; Zero Trust; multi-tenancy; CvaR; Network intrusion detection.Abstract
Release decisions for multi-tenant Zero Trust Secure Access Service Edge (SASE) platforms are difficult because a change that is acceptable in aggregate can violate a critical tenant's security objective under workload shift, missing telemetry, or configuration faults. This paper presents RA-DT, a risk-aware digital-twin framework that validates release readiness by replaying versioned release candidates against tenant-aware stress scenarios and issuing a joint risk certificate. The certificate combines criticality-weighted expected loss, unweighted aggregate loss, conditional value-at-risk (CVaR) over tenant-scenario cells, worst-tenant false-negative rate, and maximum scenario false-positive rate. To keep the evaluation reproducible and avoid claiming unavailable enterprise traces, real network-flow features and labels are taken from the public UNSW-NB15 dataset, while tenant assignments, criticality, release mutations, and stress scenarios are explicitly generated as fixed-seed synthetic context. A LightGBM detector is trained on 105,204 flows; 105 release candidates are evaluated in 12 pre-release twin scenarios and 12 independent held-out deployment scenarios, each replaying 6,000 flows. The twin readiness margin has a Spearman correlation of 0.978 with its deployment counterpart. At a matched pass count of 47 candidates, RA-DT reduces the unsafe-release escape rate from 20.4% for an aggregate-F1 gate to 2.04%, improves pass precision from 78.7% to 97.9%, and matches an expected-risk gate while providing explicit tail and tenant-level guarantees. The results support release certification as a multi-objective risk problem rather than a single-metric model test.
Downloads
References
[1] Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020, August). Zero trust architecture. NIST Special Publication 800 207. https://doi.org/10.6028/NIST.SP.800 207
[2] Chandramouli, R., & Butcher, Z. (2023, September). A zero trust architecture model for access control in cloud native applications in multi cloud environments. NIST Special Publication 800 207A. https://doi.org/10.6028/NIST.SP.800 207A
[3] Cybersecurity and Infrastructure Security Agency. (2023, April). Zero trust maturity model (Version 2.0).
[4] Ward, R., & Beyer, B. (2014). BeyondCorp: A new approach to enterprise security. ;login:, 39(6), 6–11.
[5] Syed, N. F., Shah, S. W., Shaghaghi, A., Anwar, A., Baig, Z., & Doss, R. (2022). Zero Trust Architecture (ZTA): A comprehensive survey. IEEE Access, 10, 57143–57179. https://doi.org/10.1109/ACCESS.2022.3174679
[6] Phiayura, P., & Teerakanok, S. (2023). A comprehensive framework for migrating to zero trust architecture. IEEE Access, 11, 19487–19511. https://doi.org/10.1109/ACCESS.2023.3248622
[7] Moubayed, A., Refaey, A., & Shami, A. (2019). Software Defined Perimeter (SDP): State of the art secure solution for modern networks. IEEE Network, 33(5), 226–233. https://doi.org/10.1109/MNET.2019.1800324
[8] DeCusatis, C., Liengtiraphan, P., Sager, A., & Pinelli, M. (2016). Implementing zero trust cloud networks with transport access control and first packet authentication. In Proceedings of the IEEE International Conference on Smart Cloud (pp. 5–10). https://doi.org/10.1109/SmartCloud.2016.22
[9] Cybersecurity and Infrastructure Security Agency. (2026, June). The journey to zero trust: Using secure access service edge in a modern TIC 3.0 solution.
[10] Almasan, P., Pastor, A., Barlet Ros, P., Yannuzzi, M., & Cabellos Aparicio, A. (2022). Network digital twin: Context, enabling technologies, and opportunities. IEEE Communications Magazine, 60(11), 22–27. https://doi.org/10.1109/MCOM.001.2200012
[11] Fuller, A., Fan, Z., Day, C., & Barlow, C. (2020). Digital twin: Enabling technologies, challenges and open research. IEEE Access, 8, 108952–108971. https://doi.org/10.1109/ACCESS.2020.2998358
[12] Tao, F., & Zhang, M. (2017). Digital twin shop floor: A new shop floor paradigm towards smart manufacturing. IEEE Access, 5, 20418–20427. https://doi.org/10.1109/ACCESS.2017.2756069
[13] Grieves, M., & Vickers, J. (2017). Digital twin: Mitigating unpredictable, undesirable emergent behavior in complex systems. In Transdisciplinary perspectives on complex systems (pp. 85–113). Springer. https://doi.org/10.1007/978 3 319 38756 7_4
[14] Moustafa, N., & Slay, J. (2015). UNSW NB15: A comprehensive data set for network intrusion detection systems. In Proceedings of the Military Communications and Information Systems Conference (pp. 1–6). https://doi.org/10.1109/MilCIS.2015.7348942
[15] Moustafa, N., & Slay, J. (2016). The evaluation of network anomaly detection systems: Statistical analysis of the UNSW NB15 data set and the comparison with the KDD99 data set. Information Security Journal: A Global Perspective, 25(1 3), 18–31. https://doi.org/10.1080/19393555.2015.1125974
[16] Ke, G., Meng, Q., Finley, T., Wang, T., Chen, W., Ma, W., Ye, Q., & Liu, T. Y. (2017). LightGBM: A highly efficient gradient boosting decision tree. In Advances in Neural Information Processing Systems 30 (pp. 3146–3154).
[17] Rockafellar, R. T., & Uryasev, S. (2000). Optimization of conditional value at risk. Journal of Risk, 2(3), 21–41. https://doi.org/10.21314/JOR.2000.038
[18] Duchi, J. C., & Namkoong, H. (2021). Learning models with uniform performance via distributionally robust optimization. The Annals of Statistics, 49(3), 1378–1406. https://doi.org/10.1214/20 AOS2004
[19] Guo, C., Pleiss, G., Sun, Y., & Weinberger, K. Q. (2017). On calibration of modern neural networks. In Proceedings of the 34th International Conference on Machine Learning (Vol. 70, pp. 1321–1330). PMLR.
[20] Ovadia, Y., Fertig, E., Ren, J., Nado, Z., Sculley, D., Nowozin, S., & Lakshminarayanan, B. (2019). Can you trust your model’s uncertainty? Evaluating predictive uncertainty under dataset shift. In Advances in Neural Information Processing Systems 32.
[21] Rabanser, S., Günnemann, S., & Lipton, Z. C. (2019). Failing loudly: An empirical study of methods for detecting dataset shift. In Advances in Neural Information Processing Systems 32.
[22] Saito, T., & Rehmsmeier, M. (2015). The precision recall plot is more informative than the ROC plot when evaluating binary classifiers on imbalanced datasets. PLOS ONE, 10(3), e0118432. https://doi.org/10.1371/journal.pone.0118432
[23] Kazemian, P., Varghese, G., & McKeown, N. (2012). Header space analysis: Static checking for networks. In Proceedings of the 9th USENIX Symposium on Networked Systems Design and Implementation (pp. 113–126).
[24] Khurshid, A., Zou, X., Zhou, W., Caesar, M., & Godfrey, P. B. (2013). VeriFlow: Verifying network wide invariants in real time. In Proceedings of the 10th USENIX Symposium on Networked Systems Design and Implementation (pp. 15–27).
[25] Mai, H., Khurshid, A., Agarwal, R., Caesar, M., Godfrey, P. B., & King, S. T. (2011). Debugging the data plane with Anteater. In Proceedings of the ACM SIGCOMM (pp. 290–301). https://doi.org/10.1145/2018436.2018470
[26] Al Shaer, E., & Hamed, H. (2004). Discovery of policy anomalies in distributed firewalls. In Proceedings of the IEEE INFOCOM (Vol. 4, pp. 2605–2616).
[27] Jia, Y., & Harman, M. (2011). An analysis and survey of the development of mutation testing. IEEE Transactions on Software Engineering, 37(5), 649–678. https://doi.org/10.1109/TSE.2010.62
[28] National Institute of Standards and Technology. (2012, September). Guide for conducting risk assessments. NIST Special Publication 800 30 Revision 1. https://doi.org/10.6028/NIST.SP.800 30r1
[29] Efron, B., & Tibshirani, R. J. (1993). An introduction to the bootstrap. Chapman & Hall.
[30] Ding, J., Shen, Z., & Liu, W. (2026). Game theoretic cost sensitive adversarial training for robust cloud intrusion detection against GAN based evasion attacks. Applied Sciences, 16(8), 3944. https://doi.org/10.3390/app16083944
[31] Zhao, W., Chen, T., Yang, J. S., & Qiu, L. (2026). AutoML Pipeline: A RAG enhanced code generation framework with pre validation for cloud native machine learning workflows. IEEE Access, 14, 41932–41945. https://doi.org/10.1109/ACCESS.2026.3673923
[32] Mo, T., Zhang, C., Zou, J., Guo, Z., & Rhee, M. (2026). Self evolving AI agents with dual memory for automated software testing and bug localization. IEEE Access, 14, 111086–111102. https://doi.org/10.1109/ACCESS.2026.3713401
[33] Wang, B., Wang, Z., Zhao, W., Zhang, F., & Shang, W. (2026). DRL Adapt: Deep reinforcement learning for adaptive routing convergence optimization in large scale networks. IEEE Open Journal of the Communications Society, 7, 849–863. https://doi.org/10.1109/OJCS.2026.3687441
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Transactions on Computer Science and Intelligent Systems Research

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.








