{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,27]],"date-time":"2026-06-27T10:48:01Z","timestamp":1782557281854,"version":"3.54.5"},"reference-count":49,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2026,6,27]],"date-time":"2026-06-27T00:00:00Z","timestamp":1782518400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,6,27]],"date-time":"2026-06-27T00:00:00Z","timestamp":1782518400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Netw Syst Manage"],"published-print":{"date-parts":[[2026,10]]},"DOI":"10.1007\/s10922-026-10089-8","type":"journal-article","created":{"date-parts":[[2026,6,27]],"date-time":"2026-06-27T10:42:55Z","timestamp":1782556975000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["A Hypothesis-Driven Multi-layer Zero Trust Authentication Framework"],"prefix":"10.1007","volume":"34","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6524-5736","authenticated-orcid":false,"given":"Shih-Hao","family":"Chang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kai-li","family":"Huang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7197-9912","authenticated-orcid":false,"given":"Wen-Bin","family":"Hsieh","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-7542-2374","authenticated-orcid":false,"given":"Shiang-Jiun","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,6,27]]},"reference":[{"key":"10089_CR1","unstructured":"IBM Security: Cost of a data breach report 2024. IBM. (2024). https:\/\/www.ibm.com\/reports\/data-breach. Accessed 30 Mar 2025"},{"key":"10089_CR2","first-page":"1","volume":"27","author":"J Kindervag","year":"2010","unstructured":"Kindervag, J.: Build security into your network\u2019s DNA: the zero trust network architecture. Forrester Res. 27, 1\u201316 (2010)","journal-title":"Forrester Res."},{"key":"10089_CR3","doi-asserted-by":"publisher","first-page":"207","DOI":"10.6028\/NIST.SP.800-207","volume":"800","author":"S Rose","year":"2020","unstructured":"Rose, S., Borchert, O., Mitchell, S., Connelly, S.: Zero trust architecture. NIST Spec. Publ. 800, 207 (2020). https:\/\/doi.org\/10.6028\/NIST.SP.800-207","journal-title":"NIST Spec. Publ."},{"key":"10089_CR4","volume-title":"Improving intelligence analysis with ACH","author":"RJ Heuer Jr","year":"2005","unstructured":"Heuer, R.J., Jr.: Improving intelligence analysis with ACH. Center for the Study of Intelligence, Central Intelligence Agency, Washington, DC (2005)"},{"key":"10089_CR5","volume-title":"The psychology of intelligence analysis","author":"RJ Heuer","year":"1999","unstructured":"Heuer, R.J.: The psychology of intelligence analysis. Center for the Study of Intelligence, Central Intelligence Agency, Washington, DC (1999)"},{"key":"10089_CR6","doi-asserted-by":"crossref","unstructured":"Kandula, S.R., Kassetty, N.: Context-aware multi-factor authentication in zero trust architecture: enhancing security through adaptive authentication. IEEE (2024)","DOI":"10.21428\/e90189c8.f525ef41"},{"key":"10089_CR7","doi-asserted-by":"crossref","unstructured":"Gambo, M.L., Almulhem, A.: Zero trust architecture: a systematic literature review. J. Cybersecur. Priv. (2025)","DOI":"10.36227\/techrxiv.173933211.18231232\/v1"},{"key":"10089_CR8","doi-asserted-by":"crossref","unstructured":"Ahmadi, S.: Autonomous identity-based threat segmentation in zero trust architectures. Comput. Secur. (2025)","DOI":"10.20944\/preprints202501.1191.v1"},{"issue":"6","key":"10089_CR9","first-page":"6","volume":"39","author":"R Ward","year":"2014","unstructured":"Ward, R., Beyer, B.: BeyondCorp: a new approach to enterprise security. Login 39(6), 6\u201311 (2014)","journal-title":"Login"},{"key":"10089_CR10","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.SP.800-144","volume-title":"Guidelines on security and privacy in public cloud computing (NIST SP 800\u2009\u2212\u2009144)","author":"W Jansen","year":"2011","unstructured":"Jansen, W., Grance, T.: Guidelines on security and privacy in public cloud computing (NIST SP 800\u2009\u2212\u2009144). National Institute of Standards and Technology, Gaithersburg, MD (2011). https:\/\/doi.org\/10.6028\/NIST.SP.800-144"},{"key":"10089_CR11","volume-title":"The zero trust eXtended (ZTX) ecosystem","author":"C Cunningham","year":"2018","unstructured":"Cunningham, C., et al.: The zero trust eXtended (ZTX) ecosystem. Forrester Research, Cambridge (2018)"},{"key":"10089_CR12","unstructured":"Biden, J.R.: Executive Order 14028: Improving the nation\u2019s cybersecurity. The White House, Washington, DC. (2021). https:\/\/www.federalregister.gov\/documents\/2021\/05\/17\/2021-10460\/improving-the-nations-cybersecurity. Accessed 12 May 2025"},{"key":"10089_CR13","doi-asserted-by":"publisher","first-page":"6476274","DOI":"10.1155\/2022\/6476274","volume":"2022","author":"Y He","year":"2022","unstructured":"He, Y., Huang, D., Chen, L., Ni, Y., Ma, X.: A survey on zero trust architecture: challenges and future trends. Wirel. Commun. Mob. Comput. 2022, 6476274 (2022)","journal-title":"Wirel. Commun. Mob. Comput."},{"key":"10089_CR14","doi-asserted-by":"publisher","first-page":"9947347","DOI":"10.1155\/2021\/9947347","volume":"2021","author":"S Teerakanok","year":"2021","unstructured":"Teerakanok, S., Uehara, T., Inomata, A.: Migrating to zero trust architecture: reviews and challenges. Secur. Commun. Netw. 2021, 9947347 (2021)","journal-title":"Secur. Commun. Netw."},{"key":"10089_CR15","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102911","volume":"122","author":"Z Adahman","year":"2022","unstructured":"Adahman, Z., Malik, A.W., Anwar, Z.: An analysis of zero-trust architecture and its challenges. Comput. Secur. 122, 102911 (2022)","journal-title":"Comput. Secur."},{"issue":"3","key":"10089_CR16","volume":"14","author":"M Ali","year":"2024","unstructured":"Ali, M., Abbas, A., Khan, M.U.S., Khan, S.U.: A review and comparative analysis of relevant approaches of the zero trust network model. Appl. Sci. 14(3), 1155 (2024)","journal-title":"Appl. Sci."},{"issue":"2","key":"10089_CR17","volume":"4","author":"IW Ali","year":"2024","unstructured":"Ali, I.W., Cohen, K.: Zero trust implementation in the emerging technologies era: a survey. Complex. Eng. Syst. 4(2), 8 (2024)","journal-title":"Complex. Eng. Syst."},{"key":"10089_CR18","doi-asserted-by":"publisher","DOI":"10.1016\/j.csi.2024.103832","volume":"89","author":"EB Fernandez","year":"2024","unstructured":"Fernandez, E.B., Brazhuk, A.: A critical analysis of zero trust architecture (ZTA). Comput. Stand. Interfaces. 89, 103832 (2024)","journal-title":"Comput. Stand. Interfaces."},{"key":"10089_CR19","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102436","volume":"110","author":"C Buck","year":"2021","unstructured":"Buck, C., Olenberger, C., Schweizer, A., V\u00f6lter, F., Eymann, T.: Never trust, always verify: a multivocal literature review on current knowledge and research gaps of zero trust. Comput. Secur. 110, 102436 (2021)","journal-title":"Comput. Secur."},{"issue":"1","key":"10089_CR20","doi-asserted-by":"crossref","first-page":"132","DOI":"10.3390\/s18010132","volume":"18","author":"M Frank","year":"2018","unstructured":"Frank, M., et al.: Multi-factor authentication: a survey. Sensors. 18(1), 132 (2018)","journal-title":"Sensors"},{"issue":"4","key":"10089_CR21","doi-asserted-by":"publisher","first-page":"146","DOI":"10.3390\/fi15040146","volume":"15","author":"A Kumar","year":"2023","unstructured":"Kumar, A., et al.: A systematic survey of multi-factor authentication for cloud infrastructure. Future Internet. 15(4), 146 (2023)","journal-title":"Future Internet"},{"issue":"3","key":"10089_CR22","first-page":"550","volume":"9","author":"MS Hossain","year":"2023","unstructured":"Hossain, M.S., et al.: A review of multi-factor authentication in the Internet of Healthcare Things. Digit. Commun. Netw. 9(3), 550\u2013568 (2023)","journal-title":"Digit. Commun. Netw."},{"issue":"1","key":"10089_CR23","first-page":"1","volume":"2","author":"A Omarov","year":"2018","unstructured":"Omarov, A., et al.: Multi-factor authentication: a survey. Cryptography. 2(1), 1 (2018)","journal-title":"Cryptography"},{"issue":"19","key":"10089_CR24","doi-asserted-by":"publisher","first-page":"10871","DOI":"10.3390\/app131910871","volume":"13","author":"AA Sawsan","year":"2023","unstructured":"Sawsan, A.A., et al.: Strengthening cloud security: an innovative multi-factor multilayer authentication framework for cloud user authentication. Appl. Sci. 13(19), 10871 (2023)","journal-title":"Appl. Sci."},{"issue":"4","key":"10089_CR25","first-page":"87","volume":"57","author":"AA Abin","year":"2024","unstructured":"Abin, A.A., et al.: Mouse dynamics behavioral biometrics: a survey. ACM Comput. Surv. 57(4), 87 (2024)","journal-title":"ACM Comput. Surv."},{"issue":"11","key":"10089_CR26","first-page":"3346","volume":"17","author":"R Spillane","year":"1975","unstructured":"Spillane, R.: Keyboard apparatus for personal identification. IBM Tech. Disclosure Bull. 17(11), 3346\u20133347 (1975)","journal-title":"IBM Tech. Disclosure Bull."},{"key":"10089_CR27","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.neucom.2016.11.031","volume":"230","author":"S Mondal","year":"2017","unstructured":"Mondal, S., Bours, P.: A study on continuous authentication using a combination of keystroke and mouse biometrics. Neurocomputing. 230, 1\u201322 (2017)","journal-title":"Neurocomputing"},{"issue":"4","key":"10089_CR28","first-page":"84","volume":"46","author":"KO Bailey","year":"2013","unstructured":"Bailey, K.O., et al.: Continuous authentication using behavioral biometrics. IEEE Comput. 46(4), 84\u201385 (2013)","journal-title":"IEEE Comput."},{"key":"10089_CR29","unstructured":"Mondal, M., Bours, P.: Continuous authentication using behavioural biometrics. In: Proceedings of the European Intelligence and Security Informatics Conference, Uppsala, Sweden, pp 182\u2013187. (2013)"},{"key":"10089_CR30","volume-title":"Psychology of intelligence analysis","author":"RJ Heuer","year":"1999","unstructured":"Heuer, R.J.: Psychology of intelligence analysis. Central Intelligence Agency, Washington, DC (1999)"},{"key":"10089_CR31","volume-title":"Structured analytic techniques for intelligence analysis","author":"RH Pherson","year":"2019","unstructured":"Pherson, R.H., Heuer, R.J., Jr.: Structured analytic techniques for intelligence analysis. CQ Press, Washington, DC (2019)"},{"key":"10089_CR32","doi-asserted-by":"publisher","DOI":"10.4324\/9780203994627","volume-title":"The logic of scientific discovery","author":"K Popper","year":"2005","unstructured":"Popper, K.: The logic of scientific discovery. Routledge, London (2005)"},{"key":"10089_CR33","volume-title":"The evidential foundations of probabilistic reasoning","author":"DAM Schum","year":"2001","unstructured":"Schum, D.A.M.: The evidential foundations of probabilistic reasoning. Northwestern University Press, Evanston (2001)"},{"key":"10089_CR34","unstructured":"Stirparo, F.: Analysis of competing hypotheses (ACH) for threat intelligence. SANS Internet Storm Center. https:\/\/isc.sans.edu\/diary\/22470 (2017). Accessed 30 May 2025"},{"issue":"6","key":"10089_CR35","doi-asserted-by":"publisher","first-page":"1080","DOI":"10.1002\/acp.3550","volume":"33","author":"MK Dhami","year":"2019","unstructured":"Dhami, M.K., Belton, I.K., Mandel, D.R.: The analysis of competing hypotheses in intelligence analysis. Appl. Cogn. Psychol. 33(6), 1080\u20131090 (2019)","journal-title":"Appl. Cogn. Psychol."},{"issue":"6","key":"10089_CR36","doi-asserted-by":"publisher","first-page":"941","DOI":"10.1080\/02684527.2024.2304934","volume":"39","author":"DR Mandel","year":"2024","unstructured":"Mandel, D.R.: Critical review of the analysis of competing hypotheses technique: lessons for the intelligence community. Intell. Natl. Secur. 39(6), 941\u2013962 (2024)","journal-title":"Intell. Natl. Secur."},{"issue":"3","key":"10089_CR37","first-page":"738","volume":"35","author":"G Maegherman","year":"2021","unstructured":"Maegherman, G., et al.: Test of the analysis of competing hypotheses in legal decision-making. Appl. Cogn. Psychol. 35(3), 738\u2013748 (2021)","journal-title":"Appl. Cogn. Psychol."},{"issue":"2","key":"10089_CR38","first-page":"42","volume":"17","author":"A Lemay","year":"2018","unstructured":"Lemay, A., Leblanc, S.: Iterative analysis of competing hypotheses to overcome cognitive biases in cyber decision-making. J. Inf. Warfare. 17(2), 42\u201353 (2018)","journal-title":"J. Inf. Warfare."},{"key":"10089_CR39","unstructured":"Kraven Security: Analysis of competing hypotheses: how to find plausible answers. https:\/\/kravensecurity.com\/analysis-of-competing-hypotheses\/. (2024). Accessed 28 May 2025"},{"key":"10089_CR40","unstructured":"Business Innovation Management: Analysis of competing hypotheses (ACH) process.\u00a0https:\/\/businessinnovationmanagement.com\/2020\/01\/19\/analysis-of-competing-hypotheses-ach-process\/ (2020). Accessed 2020"},{"issue":"2","key":"10089_CR41","doi-asserted-by":"publisher","first-page":"68","DOI":"10.36889\/IJCJ.2021.011","volume":"3","author":"HB De Melo","year":"2021","unstructured":"De Melo, H.B.: Does analysis of competing hypotheses (ACH) really mitigate cognitive biases? Practical implications for intelligence analysts and criminal investigators. Int. J. Crim. Justice 3(2), 68\u201382 (2021)","journal-title":"Int. J. Crim. Justice"},{"issue":"1","key":"10089_CR42","doi-asserted-by":"publisher","first-page":"1049","DOI":"10.1109\/TNSM.2021.3054356","volume":"18","author":"H Bian","year":"2021","unstructured":"Bian, H., Bai, T., Salahuddin, M.A., Limam, N., Daya, A.A., Boutaba, R.: Uncovering lateral movement using authentication logs. IEEE Trans. Netw. Serv. Manage. 18(1), 1049\u20131063 (2021)","journal-title":"IEEE Trans. Netw. Serv. Manage."},{"issue":"4","key":"10089_CR43","doi-asserted-by":"publisher","first-page":"4951","DOI":"10.1109\/TNSM.2023.3260039","volume":"20","author":"PF de Araujo-Filho","year":"2023","unstructured":"de Araujo-Filho, P.F., Naili, M., Kaddoum, G., Fapi, E.T., Zhu, Z.: Unsupervised GAN-based intrusion detection system using temporal convolutional networks and self-attention. IEEE Trans. Netw. Serv. Manage. 20(4), 4951\u20134963 (2023)","journal-title":"IEEE Trans. Netw. Serv. Manage."},{"issue":"5","key":"10089_CR44","doi-asserted-by":"publisher","first-page":"1430","DOI":"10.1109\/TITS.2017.2722688","volume":"19","author":"M Khodaei","year":"2018","unstructured":"Khodaei, M., Jin, H., Papadimitratos, P.: SECMACE: scalable and robust identity and credential management infrastructure in vehicular communication systems. IEEE Trans. Intell. Transp. Syst. 19(5), 1430\u20131444 (2018)","journal-title":"IEEE Trans. Intell. Transp. Syst."},{"key":"10089_CR45","doi-asserted-by":"publisher","first-page":"2183","DOI":"10.1109\/TIFS.2019.2958763","volume":"15","author":"K Papadamou","year":"2020","unstructured":"Papadamou, K., et al.: Killing the password and preserving privacy with device-centric and attribute-based authentication. IEEE Trans. Inf. Forensics Secur. 15, 2183\u20132193 (2020)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10089_CR46","unstructured":"Lopez-Rojas, E.A., Elmir, A., Axelsson, S.: PaySim: a financial mobile money simulator for fraud detection. In: Proceedings of the 28th European Modeling and Simulation Symposium (EMSS 2016), pp 249\u2013255. (2016)"},{"key":"10089_CR47","doi-asserted-by":"publisher","unstructured":"Moustafa, N., Slay, J.: UNSW-NB15: a comprehensive data set for network intrusion detection systems (NIDS). In: Proceedings of the Military Communications and Information Systems Conference (MilCIS), pp 1\u20136. (2015). https:\/\/doi.org\/10.1109\/MilCIS.2015.7348942","DOI":"10.1109\/MilCIS.2015.7348942"},{"key":"10089_CR48","doi-asserted-by":"publisher","first-page":"134","DOI":"10.1016\/j.eswa.2015.12.030","volume":"51","author":"AC Bahnsen","year":"2016","unstructured":"Bahnsen, A.C., Aouada, D., Stojanovic, A., Ottersten, B.: Feature engineering strategies for credit card fraud detection. Expert Syst. Appl. 51, 134\u2013142 (2016)","journal-title":"Expert Syst. Appl."},{"key":"10089_CR49","doi-asserted-by":"publisher","DOI":"10.1145\/2523813","author":"J Gama","year":"2014","unstructured":"Gama, J., \u017dliobait\u0117, I., Bifet, A., Pechenizkiy, M., Bouchachia, A.: A survey on concept drift adaptation. ACM Comput. Surv. (2014). https:\/\/doi.org\/10.1145\/2523813","journal-title":"ACM Comput. Surv."}],"container-title":["Journal of Network and Systems Management"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10922-026-10089-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10922-026-10089-8","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10922-026-10089-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,27]],"date-time":"2026-06-27T10:43:10Z","timestamp":1782556990000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10922-026-10089-8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,27]]},"references-count":49,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2026,10]]}},"alternative-id":["10089"],"URL":"https:\/\/doi.org\/10.1007\/s10922-026-10089-8","relation":{},"ISSN":["1064-7570","1573-7705"],"issn-type":[{"value":"1064-7570","type":"print"},{"value":"1573-7705","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,6,27]]},"assertion":[{"value":"7 January 2026","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"24 April 2026","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"29 April 2026","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"27 June 2026","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"117"}}