Zero-Trust Architecture for Securing IoT Edge Networks Against Advanced Persistent Threats

Authors

  • Ahmed Ramzi Rashid College of Political Science, Mustansiriyah University– Baghdad, Iraq
  • Zaydon L. Ali College of Political Science, Mustansiriyah University– Baghdad, Iraq https://orcid.org/0000-0003-3480-7198
  • Al-Doori. Ahmed Sedeeq Baker Department of Optics Technologies, College of Health and Medical Techniques /Al-Dour, Northern Technical University, Al-Dour, Iraq

DOI:

https://doi.org/10.71229/7ja6js06

Keywords:

Zero-Trust Architecture, IoT Edge Networks, Advanced Persistent Threats, Federated Learning, , Dynamic Micro-segmentation.

Abstract

The rapid expansion of Internet of Things (IoT) edge networks has introduced significant cybersecurity challenges due to the increasing number of resource-constrained devices operating outside traditional security perimeters. Conventional perimeter-based defenses are inadequate against Advanced Persistent Threats (APTs), which exploit compromised edge devices through stealthy, multi-stage attacks involving reconnaissance, lateral movement, command-and-control communication, and data exfiltration. This study presents Edge-ZTA, a lightweight Zero-Trust Architecture specifically designed for securing Industrial IoT edge environments. The proposed framework integrates three complementary components: dynamic device identity verification based on trusted attestation and behavioral fingerprinting, continuous behavioral monitoring using a Federated Deep Autoencoder for privacy-preserving anomaly detection, and Software-Defined Networking (SDN)-based dynamic micro-segmentation for real-time isolation of compromised devices. A comprehensive hybrid experimental testbed comprising physical edge devices, virtualized nodes, and 500,000 network flow records derived from benchmark cybersecurity datasets was developed to evaluate the proposed architecture under realistic APT scenarios. Experimental results demonstrated a weighted macro-average F1-score of 97.1%, with detection rates of 98.9%, 97.9%, 96.8%, and 95.9% for reconnaissance, lateral movement, command-and-control, and exfiltration attacks, respectively. Furthermore, the decentralized edge-based policy decision mechanism maintained end-to-end latency below 50 ms, while CPU utilization remained below 17%, confirming the framework's suitability for resource-constrained IoT deployments. Scalability experiments involving up to 500 edge nodes further verified stable detection accuracy and predictable latency under heterogeneous operating conditions. These findings demonstrate that Edge-ZTA provides an efficient, privacy-preserving, and scalable cybersecurity framework capable of mitigating sophisticated multi-stage cyberattacks while satisfying the stringent performance requirements of next-generation Industrial IoT infrastructures.

References

[1] Mahadik, S. S., Pawar, P. M., & Muthalagu, R. (2024). Heterogeneous IoT (HetIoT) security: techniques, challenges and open issues. Multimedia Tools and Applications, 83(12), 35371-35412.

[2] Kieras, T., Farooq, J., & Zhu, Q. (2021). I-SCRAM: A framework for IoT supply chain risk analysis and mitigation decisions. IEEE Access, 9, 29827-29840.

[3] Alshamrani, A., Myneni, S., Chowdhary, A., & Huang, D. (2019). A survey on advanced persistent threats: Techniques, solutions, challenges, and research opportunities. IEEE Communications Surveys & Tutorials, 21(2), 1851-1877.

[4] Sharma, A., Gupta, B. B., Singh, A. K., & Saraswat, V. K. (2023). Advanced persistent threats (apt): evolution, anatomy, attribution and countermeasures. Journal of ambient intelligence and humanized computing, 14(7), 9355-9381.

[5] Liao, H., Murah, M. Z., Hasan, M. K., Aman, A. H. M., Fang, J., Hu, X., & Khan, A. U. R. (2024). A survey of deep learning technologies for intrusion detection in internet of things. IEEe Access, 12, 4745-4761.

[6] Shibghatullah, A. S. B. (2023). Mitigating developed persistent threats (APTs) through machine learning-based intrusion detection systems: a comprehensive analysis. Shifra, 2023, 17-25.

[7] Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero trust architecture.NIST special publication, 800(207), 1-52.

[8] Xu, Z., Yue, Y., Di, B., & Song, L. (2026). Cloud-Edge Collaborative Zero Trust Access Control: Architecture and Scheme Design. IEEE Transactions on Mobile Computing.

[9] Hossain, E., Orthi, S. M., Siam, M. A., Mahmud, F., Goffer, M. A., & Hassan, J. (2026, March). Zero-Trust Security Models for Cloud, Edge, and IoT Environments. In 2026 IEEE International Conference for Convergence in Computing Technology (I3CTCON) (pp. 1-9). IEEE.

[10] Abo-Alian, A., Youssef, M., & Badr, N. L. (2025). A data-driven approach to prioritize MITRE ATT&CK techniques for active directory adversary emulation. Scientific Reports, 15(1), 27776.

[11] Chen, Z., Liu, J., Shen, Y., Simsek, M., Kantarci, B., Mouftah, H. T., & Djukic, P. (2022). Machine learning-enabled iot security: Open issues and challenges under advanced persistent threats. ACM Computing Surveys, 55(5), 1-37.

[12] King, I. J., & Huang, H. H. (2023). Euler: Detecting network lateral movement via scalable temporal link prediction. ACM Transactions on Privacy and Security, 26(3), 1-36.

[13] Rahaman, H., Giri, C., Roy, S. K., & Chakrabarti, A. (2025, July). Optimization and Security of AI Models for Deployment at Edge: A Comprehensive Review. In 2025 IEEE Computer Society Annual Symposium on VLSI (ISVLSI) (Vol. 1, pp. 1-6). IEEE.

[14] Khan, I. U., Khan, F. M., Haider, Z. A., & Alturise, F. (2025). Integrating AI, Blockchain, and Edge Computing for Zero-Trust IoT Security: A Comprehensive Review of Advanced Cybersecurity Framework. Computers, Materials, & Continua, 85(3), 4307.

[15] Olivia, A. (2026). Integration of Software-Defined Networking (SDN) and Zero Trust for AI-Driven Micro-Segmentation in Smart Infrastructure.

[16] Olivia, A. (2026). Integration of Software-Defined Networking (SDN) and Zero Trust for AI-Driven Micro-Segmentation in Smart Infrastructure.

[17] Hajj, S., Azar, J., Bou Abdo, J., Demerjian, J., Guyeux, C., Makhoul, A., & Ginhac, D. (2023). Cross-layer federated learning for lightweight iot intrusion detection systems. Sensors, 23(16), 7038.

[18] Canadian Institute for Cybersecurity, "CIC-IDS-2017 Dataset," University of New Brunswick, 2017. [Online]. Available: https://www.unb.ca/cic/datasets/ids-2017.html

[18] Canadian Institute for Cybersecurity, "CIC-IDS-2017 Dataset," University of New Brunswick, 2017. [Online]. Available: https://www.unb.ca/cic/datasets/ids-2017.html

[19] Canadian Institute for Cybersecurity, "CSE-CIC-IDS-2018 Dataset," University of New Brunswick, 2018. [Online]. Available: https://www.unb.ca/cic/datasets/ids-2018.html.

[20] Stratosphere Laboratory, "IoT-23 Dataset: A labeled dataset with malicious and benign IoT network traffic," Czech Technical University, 2020. [Online]. Available: https://www.stratosphereips.org/datasets-iot23

fig 1

Downloads

Published

2026-08-10

Issue

Section

Original Articles

How to Cite

Zero-Trust Architecture for Securing IoT Edge Networks Against Advanced Persistent Threats. (2026). Al-Noor Journal of Engineering Management and Computer Science, 2(3), 140-160. https://doi.org/10.71229/7ja6js06

Similar Articles

1-10 of 38

You may also start an advanced similarity search for this article.