{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,7,7]],"date-time":"2025-07-07T05:40:09Z","timestamp":1751866809621,"version":"3.41.0"},"reference-count":73,"publisher":"Frontiers Media SA","license":[{"start":{"date-parts":[[2025,7,7]],"date-time":"2025-07-07T00:00:00Z","timestamp":1751846400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["frontiersin.org"],"crossmark-restriction":true},"short-container-title":["Front. Comput. Sci."],"abstract":"<jats:p>Securing cloud-native infrastructures that integrate Multi-Factor Authentication (MFA) via FIDO2, container orchestration with Kubernetes, and Dockerized microservices remains a complex challenge due to interdependent vulnerabilities and escalating adversarial threats. To address this, we propose a web-based cybersecurity framework that combines Fuzzy Analytical Hierarchy Process (Fuzzy AHP), Domain Mapping Matrix (DMM), and fuzzy inference to perform multi-attribute risk assessment tailored to containerized environments. The method involves aggregating expert judgments to prioritize six key CIA-AAN criteria-Confidentiality, Integrity, Availability, Authentication, Authorization, and Non-repudiation-followed by structural complexity quantification using DMM enhanced with Singular Value Decomposition. These are then fused into a Complexity Resilience Index and used in a fuzzy logic system that incorporates CVE-derived indicators such as base score, impact, and exploitability. When applied to five real-world adversarial techniques, the framework produced differentiated risk outcomes: Data Destruction and Resource Hijacking emerged as High-Level Risks with scores of 70.47 and 74.60 respectively, while Endpoint DOS, Network DOS, and Inhibit System Recovery were classified as Medium-Level Risks. These results illustrate how layered threat propagation and component interdependence increase vulnerability in FIDO2-integrated orchestration settings. Compared to conventional frameworks like EBIOS and NIST RMF, our approach offers enhanced granularity in quantifying risk and simulating threat propagation. By enabling practitioners to understand not only which adversarial activities are most damaging but also why, this framework empowers more informed and proactive cybersecurity decisions-bridging the gap between technical risk modeling and real-world defense planning.<\/jats:p>","DOI":"10.3389\/fcomp.2025.1557918","type":"journal-article","created":{"date-parts":[[2025,7,7]],"date-time":"2025-07-07T05:26:52Z","timestamp":1751866012000},"update-policy":"https:\/\/doi.org\/10.3389\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Fuzzyfortify: a multi-attribute risk assessment for multi-factor authentication and cloud container orchestration"],"prefix":"10.3389","volume":"7","author":[{"given":"Mohammad","family":"Hafiz Hersyah","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Md. Delwar","family":"Hossain","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuzo","family":"Taenaka","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Youki","family":"Kadobayashi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1965","published-online":{"date-parts":[[2025,7,7]]},"reference":[{"key":"B1","doi-asserted-by":"publisher","first-page":"194","DOI":"10.1109\/SDS.2019.8768654","article-title":"\u201cOptimized availability-aware component scheduler for applications in container-based cloud,\u201d","author":"Alahmad","year":"2019","journal-title":"2019 Sixth International Conference on Software Defined Systems (SDS)"},{"key":"B2","doi-asserted-by":"publisher","first-page":"323","DOI":"10.1016\/j.cose.2017.09.011","article-title":"Improving risk assessment model of cyber security using fuzzy logic inference system","volume":"74","author":"Alali","year":"2018","journal-title":"Comput. Secur"},{"key":"B3","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/CSNet56116.2022.9955607","article-title":"\u201cA secure cloud-based architecture for monitoring cyber-physical critical infrastructures,\u201d","author":"Assump c\u00e3o","year":"2022","journal-title":"2022 6th Cyber Security in Networking Conference (CSNet)"},{"key":"B4","doi-asserted-by":"publisher","first-page":"1180","DOI":"10.23919\/MIPRO.2018.8400214","article-title":"\u201cAuthentication and authorization orchestrator for microservice-based software architectures,\u201d","author":"B\u00e1n\u00e1ti","year":"2018","journal-title":"2018 41st International Convention on Information and Communication Technology, Electronics and Microelectronics (MIPRO)"},{"key":"B5","doi-asserted-by":"publisher","first-page":"2274","DOI":"10.1016\/j.matpr.2021.06.228","article-title":"Taxonomy of cyber security metrics to measure strength of cyber security","volume":"80","author":"Bhol","year":"2023","journal-title":"Mater. Today"},{"key":"B6","doi-asserted-by":"publisher","first-page":"59","DOI":"10.1109\/CLOUD55607.2022.00022","article-title":"\u201cStay at the helm: secure kubernetes deployments via graph generation and attack reconstruction,\u201d","author":"Blaise","year":"2022","journal-title":"2022 IEEE 15th International Conference on Cloud Computing (CLOUD)"},{"key":"B7","author":"Booth","year":"2013","journal-title":"The National Vulnerability Database (NVD): Overview"},{"key":"B8","doi-asserted-by":"publisher","first-page":"61","DOI":"10.1007\/s10922-024-09835-7","article-title":"A multiobjective metaheuristic-based container consolidation model for cloud application performance improvement","volume":"32","author":"Bracke","year":"2024","journal-title":"J. Netw. Syst. Manag"},{"key":"B9","unstructured":"Containers as a service market size, share\n          \n          2023"},{"key":"B10","doi-asserted-by":"crossref","DOI":"10.1145\/3538969.3543810","article-title":"\u201cLearning state machines to monitor and detect anomalies on a kubernetes cluster,\u201d","volume-title":"Proceedings of the 17th International Conference on Availability, Reliability and Security, ARES '22","author":"Cao","year":"2022"},{"key":"B11","doi-asserted-by":"publisher","first-page":"103639","DOI":"10.1016\/j.cose.2023.103639","article-title":"Secure software development and testing: a model-based methodology","volume":"137","author":"Casola","year":"2024","journal-title":"Comput. Secur"},{"key":"B12","doi-asserted-by":"publisher","first-page":"649","DOI":"10.1016\/0377-2217(95)00300-2","article-title":"Applications of the extent analysis method on fuzzy ahp","volume":"95","author":"Chang","year":"1996","journal-title":"Eur. J. Oper. Res"},{"key":"B13","author":"Chapple","year":"2018"},{"key":"B14","author":"de la S\u00e9curit\u00e9 des Syst\u00e9mes d'Information","year":"2019","journal-title":"La m\u00e9thode ebios risk manager\u2014le guide"},{"key":"B15","doi-asserted-by":"publisher","first-page":"28956","DOI":"10.1109\/ACCESS.2020.2971024","article-title":"Two-factor mutual authentication offloading for mobile cloud computing","volume":"8","author":"Derhab","year":"2020","journal-title":"IEEE Access"},{"key":"B16","doi-asserted-by":"publisher","first-page":"103490","DOI":"10.1016\/j.cose.2023.103490","article-title":"Container security: precaution levels, mitigation strategies, and research perspectives","volume":"135","author":"Devi Priya","year":"2023","journal-title":"Comput. Secur"},{"key":"B17","doi-asserted-by":"publisher","first-page":"58","DOI":"10.1145\/3388142.3388168","article-title":"\u201cVulnerability prioritization, root cause analysis, and mitigation of secure data analytic framework implemented with Mongodb on singularity linux containers,\u201d","author":"Dissanayaka","year":"2020","journal-title":"Proceedings of the 2020 4th International Conference on Compute and Data Analysis"},{"key":"B18","doi-asserted-by":"publisher","DOI":"10.1201\/9781315369884","author":"Emrouznejad","year":"2017","journal-title":"Fuzzy analytic hierarchy process"},{"key":"B19","unstructured":"Fast identity online\n          \n          2022"},{"key":"B20","doi-asserted-by":"publisher","first-page":"103475","DOI":"10.1016\/j.cose.2023.103475","article-title":"Artificial lizard search optimized fuzzy logic approach to addressing authentication and data security challenges in p2p cloud environments","volume":"135","author":"Flavia","year":"2023","journal-title":"Comput. Secur"},{"key":"B21","doi-asserted-by":"publisher","first-page":"165","DOI":"10.1016\/S0377-2217(97)00244-0","article-title":"Aggregating individual judgments and priorities with the analytic hierarchy process","volume":"108","author":"Forman","year":"1998","journal-title":"Eur. J. Oper. Res"},{"key":"B22","doi-asserted-by":"publisher","first-page":"1073","DOI":"10.1145\/3319535.3354227","article-title":"\u201cHoudini's escape: breaking the resource rein of linux control groups,\u201d","author":"Gao","year":"2019","journal-title":"Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security"},{"key":"B23","doi-asserted-by":"publisher","first-page":"1331","DOI":"10.1080\/00207543.2018.1471236","article-title":"Fuzzy logic-based FMEA robust design: a quantitative approach for robustness against groupthink in group\/team decision-making","volume":"57","author":"Geramian","year":"2019","journal-title":"Int. J. Prod. Res"},{"key":"B24","doi-asserted-by":"publisher","first-page":"268","DOI":"10.1109\/SP40000.2020.00047","article-title":"\u201cIs fido2 the kingslayer of user authentication? A comparative usability study of fido2 passwordless authentication,\u201d","author":"Ghorbani Lyastani","year":"2020","journal-title":"2020 IEEE Symposium on Security and Privacy (SP)"},{"key":"B25","doi-asserted-by":"publisher","DOI":"10.1002\/9781119672357","author":"Grimes","year":"2020","journal-title":"Hacking Multifactor Authentication"},{"key":"B26","doi-asserted-by":"publisher","first-page":"90","DOI":"10.1186\/s13638-019-1402-8","article-title":"Secure-MQTT: an efficient fuzzy logic-based approach to detect dos attack in MQTT protocol for internet of things","volume":"2019","author":"Haripriya","year":"2019","journal-title":"EURASIP J. Wirel. Commun. Netw"},{"key":"B27","first-page":"1","article-title":"\u201cOn data protection using multi-factor authentication,\u201d","volume-title":"Proceedings of the 2019 International Conference on Information System and System Management, ISSM 2019","author":"Henricks","year":"2020"},{"key":"B28","doi-asserted-by":"publisher","first-page":"225","DOI":"10.1109\/CIoT57267.2023.10084910","article-title":"\u201cA risk assessment study: encircling docker container assets on IAAS cloud computing topology,\u201d","author":"Hersyah","year":"2023","journal-title":"2023 6th Conference on Cloud and Internet of Things (CIoT)"},{"key":"B29","doi-asserted-by":"publisher","first-page":"103789","DOI":"10.1016\/j.cose.2024.103789","article-title":"A task offloading approach based on risk assessment to mitigate edge DDOS attacks","volume":"140","author":"Huang","year":"2024","journal-title":"Comput. Secur"},{"key":"B30","volume-title":"Risk Management\u2014Guidelines","year":"2018"},{"key":"B31","doi-asserted-by":"publisher","first-page":"195","DOI":"10.2174\/2352096510666170601091846","article-title":"A security architecture for cloud computing alliance","volume":"10","author":"Jun","year":"2017","journal-title":"Recent Adv. Electr. Electr. Eng"},{"key":"B32","doi-asserted-by":"publisher","first-page":"707","DOI":"10.1109\/ICDMW51313.2020.00100","article-title":"\u201cUser authentication method using fido based password management for smart energy environment,\u201d","author":"Kim","year":"2020","journal-title":"2020 International Conference on Data Mining Workshops (ICDMW)"},{"key":"B33","volume-title":"SAFe 5.0 Distilled: Achieving Business Agility with the Scaled Agile Framework","author":"Knaster","year":"2020"},{"key":"B34","doi-asserted-by":"publisher","first-page":"172980","DOI":"10.1109\/ACCESS.2024.3501192","article-title":"Flexible and lightweight mitigation framework for distributed denial-of-service attacks in container-based edge networks using kubernetes","volume":"12","author":"Koksal","year":"2024","journal-title":"IEEE Access"},{"key":"B35","doi-asserted-by":"publisher","first-page":"288","DOI":"10.1109\/CLOUD53861.2021.00042","article-title":"\u201cIntegrity protection for kubernetes resource based on digital signature,\u201d","author":"Kudo","year":"2021","journal-title":"2021 IEEE 14th International Conference on Cloud Computing (CLOUD)"},{"key":"B36","doi-asserted-by":"publisher","first-page":"493","DOI":"10.1007\/s00521-021-06400-0","article-title":"Asset criticality and risk prediction for an effective cybersecurity risk management of cyber-physical system","volume":"34","author":"Kure","year":"2022","journal-title":"Neural Comput. Applic"},{"key":"B37","doi-asserted-by":"publisher","first-page":"123704","DOI":"10.1109\/ACCESS.2021.3108801","article-title":"High-performance software load balancer for cloud-native architecture","volume":"9","author":"Lee","year":"2021","journal-title":"IEEE Access"},{"key":"B38","doi-asserted-by":"publisher","first-page":"18351","DOI":"10.1007\/s11042-024-19613-x","article-title":"Secure container orchestration: a framework for detecting and mitigating orchestrator-level vulnerabilities","volume":"84","author":"Mahavaishnavi","year":"2024","journal-title":"Multimed. Tools Appl"},{"key":"B39","doi-asserted-by":"publisher","first-page":"2487","DOI":"10.1109\/ICSMC.2008.4811669","article-title":"\u201cThe application of the multiple-domain matrix: Considering multiple domains and dependency types in complex product design,\u201d","author":"Maurer","year":"2008","journal-title":"2008 IEEE International Conference on Systems, Man and Cybernetics"},{"key":"B40","doi-asserted-by":"publisher","first-page":"308","DOI":"10.1109\/TSE.1976.233837","article-title":"A complexity measure","volume":"2","author":"McCabe","year":"1976","journal-title":"IEEE Trans. Softw. Eng"},{"key":"B41","doi-asserted-by":"publisher","first-page":"103478","DOI":"10.1016\/j.cose.2023.103478","article-title":"Longitudinal risk-based security assessment of docker software container images","volume":"135","author":"Mills","year":"2023","journal-title":"Comput. Secur"},{"key":"B42","doi-asserted-by":"publisher","first-page":"46","DOI":"10.1109\/MSEC.2021.3094726","article-title":"Understanding the security implications of kubernetes networking","volume":"19","author":"Minna","year":"2021","journal-title":"IEEE Secur. Priv"},{"key":"B43","unstructured":"Apt28 (sandworm team)"},{"key":"B44","unstructured":"Apt38"},{"key":"B45","unstructured":"Teamtnt"},{"key":"B46","unstructured":"39468668\n          Wizardspider"},{"key":"B47","unstructured":"MITRE ATT&CK Framework for Containers\n          \n          2024"},{"key":"B48","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1109\/AINS.2017.8270418","article-title":"\u201cQuantitative risk assessment of container based cloud platform,\u201d","author":"Mostajeran","year":"2017","journal-title":"2017 IEEE Conference on Application, Information and Network Security (AINS)"},{"key":"B49","author":"Nguyen","year":"2020","journal-title":"A Design Analysis of Cloud-Based Microservices Architecture at Netflix"},{"key":"B50","volume-title":"NIST SP 800-37 Revision 1 Guide for Applying the Risk Management Framework to Federal Information Systems","year":"2012"},{"key":"B51","doi-asserted-by":"publisher","first-page":"106789","DOI":"10.1016\/j.asoc.2020.106789","article-title":"A fuzzy-ahp based prioritization of trust criteria in fog computing services","volume":"97","author":"Ogundoyin","year":"2020","journal-title":"Appl. Soft Comput"},{"key":"B52","doi-asserted-by":"publisher","first-page":"1909","DOI":"10.1109\/TDSC.2022.3165624","article-title":"Defender policy evaluation and resource allocation with MITRE ATT&CK evaluations data","volume":"20","author":"Outkin","year":"2023","journal-title":"IEEE Trans. Depend. Secure Comput"},{"key":"B53","unstructured":"Cloud architecture security cheat sheet"},{"key":"B54","unstructured":"Docker security cheat sheet"},{"key":"B55","unstructured":"Kubernetes security cheat sheet"},{"key":"B56","doi-asserted-by":"publisher","first-page":"103515","DOI":"10.1016\/j.cose.2023.103515","article-title":"A framework for analyzing authentication risks in account networks","volume":"135","author":"P\u00f6hn","year":"2023","journal-title":"Comput. Secur"},{"key":"B57","doi-asserted-by":"publisher","first-page":"103877","DOI":"10.1016\/j.im.2023.103877","article-title":"Vista: an inclusive insider threat taxonomy, with mitigation strategies","volume":"61","author":"Renaud","year":"2024","journal-title":"Inf. Manag"},{"key":"B58","doi-asserted-by":"publisher","first-page":"207","DOI":"10.1109\/SRDS.2016.033","article-title":"\u201cContinuous authentication and non-repudiation for the security of critical systems,\u201d","author":"Schiavone","year":"2016","journal-title":"2016 IEEE 35th Symposium on Reliable Distributed Systems (SRDS)"},{"key":"B59","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/ICSA.2019.00009","article-title":"\u201cData-driven software architecture for analyzing confidentiality,\u201d","author":"Seifermann","year":"2019","journal-title":"2019 IEEE International Conference on Software Architecture (ICSA)"},{"key":"B60","doi-asserted-by":"publisher","first-page":"295","DOI":"10.1002\/sys.20124","article-title":"Principles of complex systems for systems engineering","volume":"12","author":"Sheard","year":"2009","journal-title":"Syst. Eng"},{"key":"B61","author":"Sinha","year":"2014","journal-title":"Structural complexity and its implications for design of cyber-physical systems"},{"key":"B62","doi-asserted-by":"publisher","first-page":"123","DOI":"10.1007\/s00163-017-0260-9","article-title":"Pareto-optimization of complex system architecture for structural complexity and modularity","volume":"29","author":"Sinha","year":"2018","journal-title":"Res. Eng. Design"},{"key":"B63","doi-asserted-by":"publisher","first-page":"52976","DOI":"10.1109\/ACCESS.2019.2911732","article-title":"Container security: issues, challenges, and the road ahead","volume":"7","author":"Sultan","year":"2019","journal-title":"IEEE Access"},{"key":"B64","doi-asserted-by":"publisher","first-page":"103263","DOI":"10.1016\/j.cose.2023.103263","article-title":"Afpr-am: a novel fuzzy-AHP based privacy risk assessment model for strategic information management of social media platforms","volume":"130","author":"Taleby Ahvanooey","year":"2023","journal-title":"Comput. Secur"},{"key":"B65","doi-asserted-by":"publisher","first-page":"426","DOI":"10.1109\/NBiS.2014.11","article-title":"\u201cA study of risk assessment quantification in cloud computing,\u201d","author":"Tanimoto","year":"2014","journal-title":"2014 17th International Conference on Network-Based Information Systems"},{"key":"B66","doi-asserted-by":"publisher","first-page":"489","DOI":"10.1007\/s11257-023-09380-z","article-title":"An overview of consensus models for group decision-making and group recommender systems","volume":"34","author":"Tran","year":"2024","journal-title":"User Model. User-Adapt. Interact"},{"key":"B67","doi-asserted-by":"publisher","first-page":"228420","DOI":"10.1109\/ACCESS.2020.3045768","article-title":"Managing feature compatibility in kubernetes: vendor comparison and analysis","volume":"8","author":"Truyen","year":"2020","journal-title":"IEEE Access"},{"key":"B68","unstructured":"Warner\n              J. S.\n            \n          \n          35509895\n          scikit-fuzzy: Fuzzy logic toolbox for python\n          \n          2022"},{"key":"B69","doi-asserted-by":"publisher","first-page":"103140","DOI":"10.1016\/j.cose.2023.103140","article-title":"On the security of containers: Threat modeling, attack analysis, and mitigation strategies","volume":"128","author":"Wong","year":"2023","journal-title":"Comput. Secur"},{"key":"B70","doi-asserted-by":"publisher","first-page":"120526","DOI":"10.1016\/j.eswa.2023.120526","article-title":"Risk assessment modeling with application in the accounting cloud-service industry","volume":"229","author":"Wu","year":"2023","journal-title":"Expert Syst. Appl"},{"key":"B71","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1109\/ELECTRONICA52725.2021.9513723","article-title":"\u201cPredicting vulnerability type in common vulnerabilities and exposures (cve) database with machine learning classifiers,\u201d","volume-title":"2021 12th National Conference with International Participation (ELECTRONICA)","author":"Yosifova","year":"2021"},{"key":"B72","doi-asserted-by":"publisher","first-page":"338","DOI":"10.1016\/S0019-9958(65)90241-X","article-title":"Fuzzy sets","volume":"8","author":"Zadeh","year":"1965","journal-title":"Inf. Control"},{"key":"B73","doi-asserted-by":"publisher","first-page":"103473","DOI":"10.1016\/j.cose.2023.103473","article-title":"A formal approach for the identification of redundant authorization policies in kubernetes","volume":"135","author":"Zahoor","year":"2023","journal-title":"Comput. Secur"}],"container-title":["Frontiers in Computer Science"],"original-title":[],"link":[{"URL":"https:\/\/www.frontiersin.org\/articles\/10.3389\/fcomp.2025.1557918\/full","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,7]],"date-time":"2025-07-07T05:26:56Z","timestamp":1751866016000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.frontiersin.org\/articles\/10.3389\/fcomp.2025.1557918\/full"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,7,7]]},"references-count":73,"alternative-id":["10.3389\/fcomp.2025.1557918"],"URL":"https:\/\/doi.org\/10.3389\/fcomp.2025.1557918","relation":{},"ISSN":["2624-9898"],"issn-type":[{"value":"2624-9898","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,7,7]]}}}