Submitted:
01 September 2025
Posted:
02 September 2025
You are already at the latest version
Abstract
Keywords:
1. Introduction

2. Problem Identification
3. Case Study Analysis
3.1. Case I (Snowflake Data Breach 2024)
3.1.1. Background
3.1.2. Root Cause Analysis
3.1.3. Security Countermeasures
3.2. Case II (Capital One Data Breach 2019)
3.2.1. Background
3.2.2. Root Cause Analysis
3.2.3. Security Countermeasures
4. Proposed Secure System
4.1. Overview
4.2. Core Components

4.2.1. Context Collector
4.2.2. Risk Engine
4.2.3. Policy Decision Point

4.2.4. Policy Enforcement Point
4.2.5. Audit and Monitoring System
4.3. Critical Evaluation
5. Implementation Challenges and Feasibility
5.1. Challenges and Limitations
5.1.1. Integration Compatibility and Complexity
5.1.2. Financial Challenges
5.1.3. Scalability Concerns
5.1.4. User Adoption
5.2. Regulatory and Ethical Considerations
6. Evaluation and Discussion
6.1. ACASF Overview
6.2. Comparison with Role-Based Access Control (RBAC)
6.3. Comparison with Attribute-Based Access Control (ABAC)
7. Conclusions
Appendix A. Technology Stack Table
| Component | Tool/ Framework | Description |
| Context Collector | Flask, GeoIP2, Device Detector | Gathers contextual metadata |
| Risk Engine | Python, Isolation Forest | Calculates risk score |
| PDP | Open Policy Agent | Evaluates access policies |
| PEP | Flask Middleware, Redis | Enforces access decisions |
| Audit and Monitoring System | ELK Stack | Logs and visualizes events |
Appendix B. Case Study Summary Table
| Case | Date | Cause | Security Failures | Proposed Mitigation |
| Snowflake | 2024 | Stolen credentials | No MFA, static credentials | Risk Engine, Context-aware decisions |
| Capital One | 2019 | SSRF to get IAM tokens | No anomaly detection, static IAM | Dynamic access control, real-time monitoring |
Appendix C. Glossary of Terms
| ACASF | Adaptive Context-Awareness Security Framework |
| OPA | Open Policy Agent |
| ELK Stack | Elasticsearch, Logstash, Kibana |
| MFA | Multi-Factor Authentication |
| RBAC | Role-Based Access Control |
| ABAC | Attribute-Based Access Control |
Appendix D. Reference Frameworks and Visual Inspirations



8. Cybersecurity Awareness Video
References
- Ahmed, Q. W. , Garg, S., Rai, A., Ramachandran, M., Jhanjhi, N. Z., Masud, M., & Baz, M. (2022). AI-Based Resource Allocation Techniques in Wireless Sensor Internet of Things Networks in Energy Efficiency with Data Optimization. Electronics, 11, 13, 2071. [CrossRef]
- Alsaqour, R. , Majrashi, A., Alreedi, M., Alomar, K., & Abdelhaq, M. (2021). Defense in Depth: Multilayer of security. International Journal of Communication Networks and Information Security (IJCNIS), 13, 2. [CrossRef]
- apty. (24 February, 2025). Top 7 Digital Adoption Challenges & How to Solve Them (2025). Retrieved from apty: https://apty.ai/digital-adoption/digital-adoption-challenges/.
- Attaullah, M. , Ali, M., Almufareh, M. F., Ahmad, M., Hussain, L., Jhanjhi, N., & Humayun, M. (2022). Initial stage COVID-19 detection system based on patients’ symptoms and chest X-Ray images. Applied Artificial Intelligence, 36, 1. [CrossRef]
- Authentication methods at Google. (n.d.). Google Cloud. https://cloud.google.
- AWS. (2023). IAM Best Practices.https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html.
- AWS. (2023). Using Multi-Factor Authentication (MFA) in AWS.https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_mfa.html.
- Azeem, M. , Ullah, A., Ashraf, H., Jhanjhi, N., Humayun, M., Aljahdali, S., & Tabbakh, T. A. (2021). FOG-Oriented secure and lightweight data aggregation in IOMT. IEEE Access, 9, 111072–111082. [CrossRef]
- Bleeping Computer. (2024). Snowflake account hacks linked to Santander, Ticketmaster breaches. https://www.bleepingcomputer.com/news/security/snowflake-account-hacks-linked-to-santander-ticketmaster-breaches/.
- Brohi, S. N. , Jhanjhi, N., Brohi, N. N., & Brohi, M. N. (2020). Key Applications of State-of-the-Art Technologies to Mitigate and Eliminate COVID-19.pdf. Authorea Preprints. [CrossRef]
- CISA. (2023). Multi-Factor Authentication | CISA. Www.cisa.gov. https://www.cisa.gov/mfa.
- Elastic. (2025). Elastic Stack: Elasticsearch, Kibana, Beats & Logstash. Elastic. https://www.elastic.co/elastic-stack/.
- Elliott, A. , & Knight, G. (n.d.). Role Explosion: Acknowledging the Problem. Retrieved June 25, 2025, from https://knight.segfaults.net/papers/20100502%20-%20Aaron%20Elliott%20-%20WOLRDCOMP%202010%20Paper.pdf.
- Golightly, L. , Modesti, P., Garcia, R., & Chang, V. (2023). Securing Distributed Systems: A Survey on Access Control Techniques for Cloud, Blockchain, IoT and SDN. Cyber Security and Applications, 1, 100015. [CrossRef]
- Gomez, A. (25 April, 2024). Cybersecurity Ethics: Everything You Need To Know. Retrieved from OLLU: https://www.ollusa.edu/blog/cybersecurity-ethics.html.
- Hanif, M. , Ashraf, H., Jalil, Z., Jhanjhi, N. Z., Humayun, M., Saeed, S., & Almuhaideb, A. M. (2022). AI-Based wormhole attack detection techniques in wireless sensor networks. Electronics, 11, 15, 2324. [CrossRef]
- Hu, V. C. , Ferraiolo, D., Kuhn, R., Schnitzer, A., Sandlin, K., Miller, R., & Scarfone, K. (2014). Guide to Attribute Based Access Control (ABAC) Definition and Considerations. Guide to Attribute Based Access Control (ABAC) Definition and Considerations. [CrossRef]
- Humayun, M. , Jhanjhi, N. Z., Niazi, M., Amsaad, F., & Masood, I. (2022). Securing Drug Distribution Systems from Tampering Using Blockchain. Electronics 11(8), 1195. [CrossRef]
- Hussain, K. , Rahmatyar, A. R., Riskhan, B., Sheikh, M. a. U., & Sindiramutty, S. R. (2024). Threats and Vulnerabilities of Wireless Networks in the Internet of Things (IoT). 2024 IEEE 1st Karachi Section Humanitarian Technology Conference (KHI-HTC), 2, 1–8. [CrossRef]
- Introduction | Open Policy Agent. (2025). Openpolicyagent.org. https://www.openpolicyagent.org/docs.
- Jabeen, T. , Jabeen, I., Ashraf, H., Jhanjhi, N. Z., Yassine, A., & Hossain, M. S. (2023). An intelligent healthcare system using IoT in wireless sensor network. Sensors 23(11), 5055. [CrossRef]
- Jun, A. Y. M. , Jinu, B. A., Seng, L. K., Maharaiq, M. H. F. B. Z., Khongsuwan, W., Junn, B. T. K., Hao, A. a. W., & Sindiramutty, S. R. (2024). Exploring the Impact of Crypto-Ransomware on Critical Industries: Case Studies and Solutions. Preprint.org. [CrossRef]
- Kalaria, R. (8 July, 2024). Adaptive context-aware access control for IoT environments leveraging fog computing. Retrieved from Springer: https://link.springer.com/article/10.1007/s10207-024-00866-4.
- Gill, S. H. , Razzaq, M. A., Ahmad, M., Almansour, F. M., Haq, I. U., Jhanjhi, N. Z.,... & Masud, M. (2022). Security and privacy aspects of cloud computing: a smart campus case study. Intelligent Automation & Soft Computing, 31, 1, 117–128.
- 9.
- Khan, S. , Kabanov, I., Hua, Y., & Madnick, S. (2022). A systematic analysis of the Capital One data breach: Critical lessons learned, ACM Transactions on Privacy and Security, 26(1), Article 3. [CrossRef]
- Kiyani, F. F. , Hamid, B., Humayun, M., Sindiramutty, S. R. a. L., & Chowdhury, S. (2024). Discovery of Influential Publications Using Research Article’s Usage Context. 2024 International Conference on Emerging Trends in Networks and Computer Communications (ETNCC), 1–7. [CrossRef]
- Kosmos. (2024). Understanding the Snowflake Data Breach and Its Implications. Retrieved June 9, 2025, from https://www.1kosmos.com/authentication/understanding-the-snowflake-data-breach-and-its-implications/.
- Krishnan, S. , Thangaveloo, R., Rahman, S. B. A., & Sindiramutty, S. R. (2021). Smart Ambulance Traffic Control system. Trends in Undergraduate Research 4(1), c28–34. [CrossRef]
- Kunal Relan, & Springerlink (Online Service. (2019). Building REST APIs with Flask : Create Python Web Services with MySQL. Apress.
- Linqiang, Y. , Sindiramutty, S. R. a. L., Ashraf, H., Muzammal, S. M., Balakrishnan, S. a. P., Gupta, S., & Kavita, N. (2024). Intelligent Household Waste Classification System Based on Machine Learning. 2024 International Conference on Emerging Trends in Networks and Computer Communications (ETNCC), 760–768. [CrossRef]
- Manchuri, A. , Kakera, A., Saleh, A., & Raja, S. (2024). pplication of Supervised Machine Learning Models in Biodiesel Production Research - A Short Review. Borneo Journal of Sciences and Technology. [CrossRef]
- Mandiant. (2024, ). UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion. Retrieved fromhttps://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft-extortion.
- Muscat, M. (2019, July 31). How an SSRF misconfiguration led to a leak of 100 million financial records. Acunetix.https://www.acunetix.com/blog/web-security-zone/ssrf-misconfiguration-leak-one-hundred-million-financial-records/?utm_source=chatgpt.com.
- Aldughayfiq, B. , Ashfaq, F., Jhanjhi, N. Z., & Humayun, M. (2023, April). Yolo-based deep learning model for pressure ulcer detection and classification. In Healthcare (Vol. 11, No. 9, p. 1222). MDPI.
- Muzammal, S. M. , Murugesan, R. K., Jhanjhi, N. Z., & Jung, L. T. (2020). SMTrust: Proposing Trust-Based Secure Routing Protocol for RPL Attacks for IoT Applications. 2020 International Conference on Computational Intelligence (ICCI), 305–310. [CrossRef]
- Nieles, M. , Dempsey, K., & Pillitteri, V. Y. (2017). An introduction to information security. An Introduction to Information Security 1(1), 81. [CrossRef]
- Ravichandran, N. , Tewaraja, T., Rajasegaran, V., Kumar, S. S., Gunasekar, S. K. L., & Sindiramutty, S. R. (2024). Comprehensive Review Analysis and Countermeasures for Cybersecurity Threats: DDoS, Ransomware, and Trojan Horse Attacks. preprint.org. [CrossRef]
- Ridha Khedri, Jones, O., & Alabbad, M. (2017). Defense in Depth Formulation and Usage in Dynamic Access Control. Lecture Notes in Computer Science, 253–274. [CrossRef]
- Riza, A. Z. B. M. , Jennsen, L., Anggani, P., Rafeen, A. I., Ruth, P. N. J., Sookun, D., Sookun, V., Yusri, N. a. Z. B. M., Sern, L. J., Luximon, L., Omer, M. L., & Sindiramutty, S. R. (2025). Leveraging Machine Learning and AI to Combat Modern Cyber Threats. Preprints.org. [CrossRef]
- Rose, S. , Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero trust architecture. NIST Special Publication 800-207, 800-207. [CrossRef]
- Saeed, S. , Abdullah, A., Jhanjhi, N. Z., Naqvi, M., & Nayyar, A. (2022). New techniques for efficiently k-NN algorithm for brain tumor detection. Multimedia Tools and Applications, 81, 13, 18595–18616. [CrossRef]
- ScienceDirect. (2024). Big Data System. Retrieved June 9, 2025, from https://www.sciencedirect.com/topics/computer-science/big-data-system.
- Seng, Y. J. , Cen, T. Y., Raslan, M. a. H. B. M., Subramaniam, M. R., Xin, L. Y., Kin, S. J., Long, M. S., & Sindiramutty, S. R. (2024). In-Depth Analysis and Countermeasures for Ransomware Attacks: Case Studies and Recommendations. Preprints.org. [CrossRef]
- Shah, I. A. , Jhanjhi, N. Z., & Laraib, A. (2022). Cybersecurity and blockchain usage in contemporary business. In Advances in information security, privacy, and ethics book series (pp. 49–64). [CrossRef]
- Sindiramutty, S. R. , Jhanjhi, N. Z., Tan, C. E., Tee, W. J., Lau, S. P., Jazri, H., Ray, S. K., & Zaheer, M. A. (2024). IoT and AI-Based Smart Solutions for the Agriculture Industry. In Advances in computational intelligence and robotics book series (pp. 317–351). [CrossRef]
- Sindiramutty, S. R. , Jhanjhi, N. Z., Tan, C. E., Yun, K. J., Manchuri, A. R., Ashraf, H., Murugesan, R. K., Tee, W. J., & Hussain, M. (2024). Data security and privacy concerns in drone operations. In Advances in information security, privacy, and ethics book series (pp. 236–290). [CrossRef]
- Sindiramutty, S. R. , Jhanjhi, N., Tan, C. E., Lau, S. P., Muniandy, L., Gharib, A. H., Ashraf, H., & Murugesan, R. K. (2024). Industry 4.0. In Advances in logistics, operations, and management science book series (pp. 342–405). [CrossRef]
- Sindiramutty, S. R. , Prabagaran, K. R. V., Jhanjhi, N. Z., Ghazanfar, M. A., Malik, N. A., & Soomro, T. R. (2024). Security Considerations in Generative AI for web Applications. In Advances in information security, privacy, and ethics book series (pp. 281–332). [CrossRef]
- Sindiramutty, S. R. , Prabagaran, K. R. V., Jhanjhi, N. Z., Murugesan, R. K., Brohi, S. N., & Masud, M. (2024). Generative AI in network security and intrusion detection. In Advances in information security, privacy, and ethics book series (pp. 77–124). [CrossRef]
- Sindiramutty, S. R. , Tan, C. E., & Wei, G. W. (2024). Eyes in the sky. In Advances in information security, privacy, and ethics book series (pp. 405–451). [CrossRef]
- Waheed, A. , Seegolam, B., Jowaheer, M. F., Sze, C. L. X., Hua, E. T. F., & Sindiramutty, S. R. (2024). Zero-Day Exploits in Cybersecurity: Case Studies and Countermeasure. Preprints.org. [CrossRef]
- Watkins, S. G. (2022). Iso/Iec 27001: 2022: An Introduction to Information Security and the ISMS Standard. It Governance Limited.
- Weiqi, X. , Hooi, S. T. C., Sindiramutty, S. R. a. L., Asirvatham, D. a. L., Kumar, D., & Verma, S. (2024). Surface Anomaly Detection Using Machine Learning Technique. 2024 International Conference on Emerging Trends in Networks and Computer Communications (ETNCC), 1–7. [CrossRef]
- Wen, B. O. T. , Syahriza, N., Xian, N. C. W., Wei, N. G., Shen, T. Z., Hin, Y. Z., Sindiramutty, S. R., & Nicole, T. Y. F. (2023). Detecting cyber threats with a Graph-Based NIDPS. In Advances in logistics, operations, and management science book series (pp. 36–74). [CrossRef]
- Working with JSON - Learn web development | MDN. (2024, December 19). MDN Web Docs. https://developer.mozilla.org/en-US/docs/Learn_web_development/Core/Scripting/JSON.
- Xun, A. T. , En, L. a. Z., Shen, L. T., Xin, A. N., Soon, W. H., Jun, W. Z., Ramachandra, H., Xinghao, G., Khant, N. M., Weitao, F., & Sindiramutty, S. R. (2025). Building Trust in Cloud Computing:Strategies for Resilient Security. Preprints.org. [CrossRef]
- Ying, X. , Murugesan, R. K., Sindiramutty, S. R., Wei, G. W., Balakrishnan, S., Kumar, D., & Verma, S. (2024). Scene Text Recognition using Deep Learning Techniques. 024 International Conference on Emerging Trends in Networks and Computer Communications (ETNCC), 1–9. [CrossRef]
- Jhanjhi, N. (2024). Comparative analysis of frequent pattern mining algorithms on healthcare data. In 2024 IEEE 9th International Conference on Engineering Technologies and Applied Sciences (ICETAS) (pp. 1-10). IEEE. [CrossRef]
- Jhanjhi, N. Z. (2025). Investigating the influence of loss functions on the performance and interpretability of machine learning models. In S. Pal & Á. Rocha (Eds.), Proceedings of 4th International Conference on Mathematical Modeling and Computational Science. ICMMCS 2025. Lecture Notes in Networks and Systems, vol 1399 (pp. 100-110). Springer. [CrossRef]
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2025 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).