A STRIDE-Based Cybersecurity Framework for Threat Detection in Federated Identity and Access Management Systems
Abstract
Federated Identity and Access Management (IAM) systems enable users to access multiple independently administered services through shared identity and authentication mechanisms. Although federation improves usability, scalability, and centralized identity governance, it also creates security dependencies across identity providers, service providers, authentication protocols, token exchanges, and trust relationships. A compromise at one component may consequently propagate across organizational boundaries. This paper proposes a STRIDE-based cybersecurity framework for systematic threat detection in federated IAM environments, with particular emphasis on federated Single Sign-On (SSO) and Multi-Factor Authentication (MFA). The framework maps major federated IAM components and trust boundaries to the STRIDE threat categories of spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege. The methodological design combines architectural threat decomposition, trust-boundary analysis, threat-to-control mapping, and structured assessment of observable security events. Statistical concepts concerning correlated binary outcomes are incorporated to support future empirical evaluation where authentication or detection observations are non-independent. The proposed framework identifies identity-provider compromise, assertion or token manipulation, authentication-event repudiation, sensitive identity-information exposure, federation service disruption, and privilege escalation as principal threat classes. The analysis indicates that security controls should not be evaluated independently at individual components because federated authentication creates interdependent attack surfaces. The framework therefore provides a structured foundation for threat detection, risk prioritization, and security-control validation in federated IAM architectures.
Keywords
References
Most read articles by the same author(s)
- Dr. Jakob R. Neumann, Prof. Leila F. Mahmoud, Securing the Virtual Meeting Space: An Analysis of Cybersecurity Risks and Mitigation Strategies for Video Conferencing Platforms , International Journal of Cyber Threat Intelligence and Secure Networking: Vol. 2 No. 09 (2025): Volume 02 Issue 09
- Aghasi Gevorgyan, Automation of Compliance Control Processes According to PCI DSS Standards in Hybrid Cloud Environments , International Journal of Cyber Threat Intelligence and Secure Networking: Vol. 3 No. 04 (2026): Volume 03 Issue 04
- Dr. Marcus A. Rodriguez, A Longitudinal Analysis of Cybersecurity Technology and Innovation: A Technology Mining Approach Using Bibliometric and Patent Analysis , International Journal of Cyber Threat Intelligence and Secure Networking: Vol. 3 No. 05 (2026): Volume 03 Issue 05
- Dr. Nguyen Van Minh, Dr. Tran Thi Lan, Cross-Layer Protocol Design and Integration Strategies for IoT and IoRT Convergence: An Analytical Review of Enabling Technologies, Challenges, and Emerging Solutions , International Journal of Cyber Threat Intelligence and Secure Networking: Vol. 3 No. 08 (2026): Volume 03 Issue 08
- Prof. Hans-Peter Vogel, Dr. Farah Al-Dabbagh, UNINTENDED CONSEQUENCES AND SPILLOVER EFFECTS IN OFFENSIVE CYBER OPERATIONS: A SYSTEMATIC LITERATURE REVIEW , International Journal of Cyber Threat Intelligence and Secure Networking: Vol. 1 No. 01 (2024): Volume 01 Issue 01
- Dr. Arjun Pratap Singh, Dr. Neha Verma, Research on Unusual Transmission Pattern Recognition in Telecommunication Infrastructure Using Fuzzy Equation Approach , International Journal of Cyber Threat Intelligence and Secure Networking: Vol. 3 No. 04 (2026): Volume 03 Issue 04
- Dr. Chinedu Okafor, Dr. Aisha Bello, An Intelligent Risk-Aware Security Framework for Detection and Prevention of Cyber Attacks on Critical Power Grid Infrastructure in Nigeria’s Electricity Sector , International Journal of Cyber Threat Intelligence and Secure Networking: Vol. 3 No. 08 (2026): Volume 03 Issue 08
- Mr. Kapil Ahir, Modern Software Management Practices in Agile and DevOps Environments: A Review , International Journal of Cyber Threat Intelligence and Secure Networking: Vol. 3 No. 07 (2026): Volume 03 Issue 07
- Dr. Ahmed Raza, Dr. Sanaullah Khan, A Context-Aware Input Normalization Framework for Medical Prescription Interpretation in Text-to-Speech Systems for Clinical Decision Support Applications , International Journal of Cyber Threat Intelligence and Secure Networking: Vol. 3 No. 08 (2026): Volume 03 Issue 08
- Mr. Anoop Sunarty, AI-Driven Predictive Model for Osteoporosis Risk Assessment , International Journal of Cyber Threat Intelligence and Secure Networking: Vol. 3 No. 09 (2026): Volume 03 Issue 09
Similar Articles
- Aghasi Gevorgyan, Automation of Compliance Control Processes According to PCI DSS Standards in Hybrid Cloud Environments , International Journal of Cyber Threat Intelligence and Secure Networking: Vol. 3 No. 04 (2026): Volume 03 Issue 04
- Chinedu Okafor, Amina Yusuf Bello, A Strategic HR Framework for Reducing Employee Attrition and Enhancing Talent Acquisition in the Indian Banking Sector , International Journal of Cyber Threat Intelligence and Secure Networking: Vol. 3 No. 09 (2026): Volume 03 Issue 09
- Haruto Nakamura, Yui Takahashi, Adaptive Authentication Framework for Agentic AI Ecosystems: Protocol Design, Trust Evaluation, and Security Analysis , International Journal of Cyber Threat Intelligence and Secure Networking: Vol. 3 No. 09 (2026): Volume 03 Issue 09
- Ashutosh Palia, CMDB Data Governance and Business Continuity: Identifying Research Gaps in AI-Driven IT Operations , International Journal of Cyber Threat Intelligence and Secure Networking: Vol. 3 No. 09 (2026): Volume 03 Issue 09
- Dr. Tanvi Das, James D. Walker, A FEDERATED MULTI-MODAL SYSTEM FOR INSIDER THREAT DETECTION IN ENERGY INFRASTRUCTURE USING BIOMETRIC AND CYBER DATA , International Journal of Cyber Threat Intelligence and Secure Networking: Vol. 2 No. 01 (2025): Volume 02 Issue 01
- Mr. Kapil Ahir, Modern Software Management Practices in Agile and DevOps Environments: A Review , International Journal of Cyber Threat Intelligence and Secure Networking: Vol. 3 No. 07 (2026): Volume 03 Issue 07
- Nguyen Minh Khoa, Tran Thi Lan Anh, Strategic Business Transformation through Data Analytics, Sustainable Practices, and Innovation Management , International Journal of Cyber Threat Intelligence and Secure Networking: Vol. 3 No. 09 (2026): Volume 03 Issue 09
- Dr. Elena Petrova, Dr. Hassan Al-Mansoori, EVALUATING AND ENHANCING CYBERSECURITY AND RESILIENCE IN HEALTHCARE: A UNIFIED RISK AND COMPLIANCE FRAMEWORK , International Journal of Cyber Threat Intelligence and Secure Networking: Vol. 2 No. 05 (2025): Volume 02 Issue 05
- Dr. Arben Kola, Dr. Elira Hoxha, Dr. Gentian Leka, Study of Threat Evaluation and Forecasting Framework for Communication Infrastructure Using Neural Intelligence Techniques , International Journal of Cyber Threat Intelligence and Secure Networking: Vol. 3 No. 04 (2026): Volume 03 Issue 04
- Dr. Lin K. Chen, A Novel Energy-Efficient and Secure Opportunistic Routing Protocol for Data Transmission in Wireless Sensor Networks , International Journal of Cyber Threat Intelligence and Secure Networking: Vol. 3 No. 06 (2026): Volume 03 Issue 06
You may also start an advanced similarity search for this article.