A Risk-Aware Digital Twin Framework for Release-Readiness Validation of Multi-Tenant Zero Trust SASE Systems

Authors

  • Jianbo Ding SonicWall, Milpitas, CA 95035, USA
  • Dai Teng The Siebel School of Computing and Data Science, University of Illinois Urbana-Champaign, Champaign, IL 61801, USA

DOI:

https://doi.org/10.62051/f19vvd53

Keywords:

Digital twin; Release readiness; SASE; Zero Trust; multi-tenancy; CvaR; Network intrusion detection.

Abstract

Release decisions for multi-tenant Zero Trust Secure Access Service Edge (SASE) platforms are difficult because a change that is acceptable in aggregate can violate a critical tenant's security objective under workload shift, missing telemetry, or configuration faults. This paper presents RA-DT, a risk-aware digital-twin framework that validates release readiness by replaying versioned release candidates against tenant-aware stress scenarios and issuing a joint risk certificate. The certificate combines criticality-weighted expected loss, unweighted aggregate loss, conditional value-at-risk (CVaR) over tenant-scenario cells, worst-tenant false-negative rate, and maximum scenario false-positive rate. To keep the evaluation reproducible and avoid claiming unavailable enterprise traces, real network-flow features and labels are taken from the public UNSW-NB15 dataset, while tenant assignments, criticality, release mutations, and stress scenarios are explicitly generated as fixed-seed synthetic context. A LightGBM detector is trained on 105,204 flows; 105 release candidates are evaluated in 12 pre-release twin scenarios and 12 independent held-out deployment scenarios, each replaying 6,000 flows. The twin readiness margin has a Spearman correlation of 0.978 with its deployment counterpart. At a matched pass count of 47 candidates, RA-DT reduces the unsafe-release escape rate from 20.4% for an aggregate-F1 gate to 2.04%, improves pass precision from 78.7% to 97.9%, and matches an expected-risk gate while providing explicit tail and tenant-level guarantees. The results support release certification as a multi-objective risk problem rather than a single-metric model test.

Downloads

Download data is not yet available.

References

[1] Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020, August). Zero trust architecture. NIST Special Publication 800 207. https://doi.org/10.6028/NIST.SP.800 207

[2] Chandramouli, R., & Butcher, Z. (2023, September). A zero trust architecture model for access control in cloud native applications in multi cloud environments. NIST Special Publication 800 207A. https://doi.org/10.6028/NIST.SP.800 207A

[3] Cybersecurity and Infrastructure Security Agency. (2023, April). Zero trust maturity model (Version 2.0).

[4] Ward, R., & Beyer, B. (2014). BeyondCorp: A new approach to enterprise security. ;login:, 39(6), 6–11.

[5] Syed, N. F., Shah, S. W., Shaghaghi, A., Anwar, A., Baig, Z., & Doss, R. (2022). Zero Trust Architecture (ZTA): A comprehensive survey. IEEE Access, 10, 57143–57179. https://doi.org/10.1109/ACCESS.2022.3174679

[6] Phiayura, P., & Teerakanok, S. (2023). A comprehensive framework for migrating to zero trust architecture. IEEE Access, 11, 19487–19511. https://doi.org/10.1109/ACCESS.2023.3248622

[7] Moubayed, A., Refaey, A., & Shami, A. (2019). Software Defined Perimeter (SDP): State of the art secure solution for modern networks. IEEE Network, 33(5), 226–233. https://doi.org/10.1109/MNET.2019.1800324

[8] DeCusatis, C., Liengtiraphan, P., Sager, A., & Pinelli, M. (2016). Implementing zero trust cloud networks with transport access control and first packet authentication. In Proceedings of the IEEE International Conference on Smart Cloud (pp. 5–10). https://doi.org/10.1109/SmartCloud.2016.22

[9] Cybersecurity and Infrastructure Security Agency. (2026, June). The journey to zero trust: Using secure access service edge in a modern TIC 3.0 solution.

[10] Almasan, P., Pastor, A., Barlet Ros, P., Yannuzzi, M., & Cabellos Aparicio, A. (2022). Network digital twin: Context, enabling technologies, and opportunities. IEEE Communications Magazine, 60(11), 22–27. https://doi.org/10.1109/MCOM.001.2200012

[11] Fuller, A., Fan, Z., Day, C., & Barlow, C. (2020). Digital twin: Enabling technologies, challenges and open research. IEEE Access, 8, 108952–108971. https://doi.org/10.1109/ACCESS.2020.2998358

[12] Tao, F., & Zhang, M. (2017). Digital twin shop floor: A new shop floor paradigm towards smart manufacturing. IEEE Access, 5, 20418–20427. https://doi.org/10.1109/ACCESS.2017.2756069

[13] Grieves, M., & Vickers, J. (2017). Digital twin: Mitigating unpredictable, undesirable emergent behavior in complex systems. In Transdisciplinary perspectives on complex systems (pp. 85–113). Springer. https://doi.org/10.1007/978 3 319 38756 7_4

[14] Moustafa, N., & Slay, J. (2015). UNSW NB15: A comprehensive data set for network intrusion detection systems. In Proceedings of the Military Communications and Information Systems Conference (pp. 1–6). https://doi.org/10.1109/MilCIS.2015.7348942

[15] Moustafa, N., & Slay, J. (2016). The evaluation of network anomaly detection systems: Statistical analysis of the UNSW NB15 data set and the comparison with the KDD99 data set. Information Security Journal: A Global Perspective, 25(1 3), 18–31. https://doi.org/10.1080/19393555.2015.1125974

[16] Ke, G., Meng, Q., Finley, T., Wang, T., Chen, W., Ma, W., Ye, Q., & Liu, T. Y. (2017). LightGBM: A highly efficient gradient boosting decision tree. In Advances in Neural Information Processing Systems 30 (pp. 3146–3154).

[17] Rockafellar, R. T., & Uryasev, S. (2000). Optimization of conditional value at risk. Journal of Risk, 2(3), 21–41. https://doi.org/10.21314/JOR.2000.038

[18] Duchi, J. C., & Namkoong, H. (2021). Learning models with uniform performance via distributionally robust optimization. The Annals of Statistics, 49(3), 1378–1406. https://doi.org/10.1214/20 AOS2004

[19] Guo, C., Pleiss, G., Sun, Y., & Weinberger, K. Q. (2017). On calibration of modern neural networks. In Proceedings of the 34th International Conference on Machine Learning (Vol. 70, pp. 1321–1330). PMLR.

[20] Ovadia, Y., Fertig, E., Ren, J., Nado, Z., Sculley, D., Nowozin, S., & Lakshminarayanan, B. (2019). Can you trust your model’s uncertainty? Evaluating predictive uncertainty under dataset shift. In Advances in Neural Information Processing Systems 32.

[21] Rabanser, S., Günnemann, S., & Lipton, Z. C. (2019). Failing loudly: An empirical study of methods for detecting dataset shift. In Advances in Neural Information Processing Systems 32.

[22] Saito, T., & Rehmsmeier, M. (2015). The precision recall plot is more informative than the ROC plot when evaluating binary classifiers on imbalanced datasets. PLOS ONE, 10(3), e0118432. https://doi.org/10.1371/journal.pone.0118432

[23] Kazemian, P., Varghese, G., & McKeown, N. (2012). Header space analysis: Static checking for networks. In Proceedings of the 9th USENIX Symposium on Networked Systems Design and Implementation (pp. 113–126).

[24] Khurshid, A., Zou, X., Zhou, W., Caesar, M., & Godfrey, P. B. (2013). VeriFlow: Verifying network wide invariants in real time. In Proceedings of the 10th USENIX Symposium on Networked Systems Design and Implementation (pp. 15–27).

[25] Mai, H., Khurshid, A., Agarwal, R., Caesar, M., Godfrey, P. B., & King, S. T. (2011). Debugging the data plane with Anteater. In Proceedings of the ACM SIGCOMM (pp. 290–301). https://doi.org/10.1145/2018436.2018470

[26] Al Shaer, E., & Hamed, H. (2004). Discovery of policy anomalies in distributed firewalls. In Proceedings of the IEEE INFOCOM (Vol. 4, pp. 2605–2616).

[27] Jia, Y., & Harman, M. (2011). An analysis and survey of the development of mutation testing. IEEE Transactions on Software Engineering, 37(5), 649–678. https://doi.org/10.1109/TSE.2010.62

[28] National Institute of Standards and Technology. (2012, September). Guide for conducting risk assessments. NIST Special Publication 800 30 Revision 1. https://doi.org/10.6028/NIST.SP.800 30r1

[29] Efron, B., & Tibshirani, R. J. (1993). An introduction to the bootstrap. Chapman & Hall.

[30] Ding, J., Shen, Z., & Liu, W. (2026). Game theoretic cost sensitive adversarial training for robust cloud intrusion detection against GAN based evasion attacks. Applied Sciences, 16(8), 3944. https://doi.org/10.3390/app16083944

[31] Zhao, W., Chen, T., Yang, J. S., & Qiu, L. (2026). AutoML Pipeline: A RAG enhanced code generation framework with pre validation for cloud native machine learning workflows. IEEE Access, 14, 41932–41945. https://doi.org/10.1109/ACCESS.2026.3673923

[32] Mo, T., Zhang, C., Zou, J., Guo, Z., & Rhee, M. (2026). Self evolving AI agents with dual memory for automated software testing and bug localization. IEEE Access, 14, 111086–111102. https://doi.org/10.1109/ACCESS.2026.3713401

[33] Wang, B., Wang, Z., Zhao, W., Zhang, F., & Shang, W. (2026). DRL Adapt: Deep reinforcement learning for adaptive routing convergence optimization in large scale networks. IEEE Open Journal of the Communications Society, 7, 849–863. https://doi.org/10.1109/OJCS.2026.3687441

Downloads

Published

13-08-2026

How to Cite

Ding, J., & Teng, D. (2026). A Risk-Aware Digital Twin Framework for Release-Readiness Validation of Multi-Tenant Zero Trust SASE Systems. Transactions on Computer Science and Intelligent Systems Research, 13, 247-259. https://doi.org/10.62051/f19vvd53