STRENGTHENING CLOUD SECURITY WITH MACHINE LEARNINGDRIVEN MULTI-FACTOR AUTHENTICATION AND ADAPTIVE CRYPTOGRAPHY
DOI:
https://doi.org/10.64751/tq09sj02Abstract
The rapid expansion of cloud computing has transformed modern information technology by enabling scalable infrastructure, elastic resource allocation, remote collaboration, distributed application deployment, and on-demand access to computing services. However, the increasing migration of sensitive information and critical workloads to public, private, hybrid, and multicloud environments has created significant security challenges involving credential theft, account takeover, phishing, session hijacking, insider threats, unauthorized access, behavioral anomalies, and cryptographic compromise. Conventional password-based authentication provides insufficient protection against stolen credentials, while static multi-factor authentication often applies identical verification requirements regardless of user behavior, device trust, contextual risk, or resource sensitivity. Similarly, fixed cryptographic configurations may provide limited adaptability when threat conditions, access patterns, and workload criticality change dynamically. This research proposes an intelligent cloud security framework that integrates Machine Learning-Driven Multi-Factor Authentication (ML-MFA) with Adaptive Cryptography to provide contextaware identity verification and dynamically coordinated data protection. The proposed framework continuously analyzes user behavior, device fingerprints, login history, geolocation consistency, access time, IP reputation, network characteristics, session activity, privilege level, resource sensitivity, and threat intelligence. Machine learning algorithms including Random Forest, Support Vector Machine, XGBoost, Isolation Forest, and Multilayer Perceptron are employed to identify anomalous access behavior and estimate dynamic authentication risk. Based on the calculated risk level, the system adaptively selects appropriate authentication factors such as passwords, passkeys, one-time passwords, authenticator applications, biometric verification, and hardware security keys. The adaptive cryptography module simultaneously evaluates authentication confidence, data sensitivity, device trust, session anomalies, and workload criticality to determine suitable approved encryption policies, key-protection requirements, sessionkey lifetimes, and rekeying frequencies without reducing protection below mandatory security baselines. A hybrid decision engine combines machine learning predictions, behavioral anomalies, authentication confidence, resource sensitivity, and cryptographic posture to classify access requests as Low Risk, Medium Risk, High Risk, or Critical Risk. The proposed architecture consists of five interconnected layers: Cloud Access and Context Acquisition, Security Data Preprocessing and Behavioral Intelligence, Machine Learning-Driven MFA and Adaptive Cryptography, Risk Assessment and Security Enforcement, and Cloud Application and User layers. Illustrative conceptual evaluation demonstrates that the proposed framework can achieve higher security detection accuracy, precision, recall, F1-score, adaptive security efficiency, and faster analytical decision response than password-based authentication, conventional static MFA, and isolated risk-based authentication. The framework provides a scalable foundation for intelligent cloud protection across enterprise systems, financial platforms, healthcare clouds, educational services, government infrastructures, and multicloud environments.
Downloads
Published
Issue
Section
License

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.







