ORIGINAL RESEARCH article

Front. Comput. Sci.

Sec. Computer Security

Volume 7 - 2025 | doi: 10.3389/fcomp.2025.1557918

Fuzzyfortify: A Multi-Attribute Risk Assessment for Multi-Factor Authentication and Cloud Container Orchestration

Provisionally accepted
Mohammad  Hafiz HersyahMohammad Hafiz Hersyah1,2*MD  Delwar HossainMD Delwar Hossain3Yuzo  TaenakaYuzo Taenaka1Youki  KadobayashiYouki Kadobayashi1
  • 1Nara Institute of Science and Technology (NAIST), Ikoma, Japan
  • 2Andalas University, Padang, West Sumatra, Indonesia
  • 3Angelo State University, San Angelo, Texas, United States

The final, formatted version of the article will be published soon.

Securing Multi-Factor Authentication (MFA) and container orchestration technologies such as FIDO2, Kubernetes, and Docker in cloud computing environments requires addressing internal and external threats, misconfigurations, and architectural interdependencies. Without effective methods to prioritize these risks, attackers can exploit systemic vulnerabilities to launch sophisticated attacks. Existing risk assessment frameworks often rely on static scoring and subjective judgment, limiting their ability to address complexity and uncertainty. To overcome these limitations, this study proposes a three-step multi-attribute risk assessment framework.First, a complexity resilience index is developed by modifying the fuzzy analytical hierarchy process (AHP) to prioritize CIA (Confidentiality, Integrity, Availability) and AAN (Authentication, Authorization, Non-Repudiation) properties with a domain mapping matrix to quantify structural complexity. Second, fuzzy logic is applied to integrate this index with real-world CVE metrics, enabling adaptive and uncertainty-aware risk prioritization. Third, the entire framework is deployed as a web-based tool to facilitate practitioner adoption. This framework uses MITRE ATT&CK threat intelligence to stay aligned with real-world threats. It improves current methods by measuring system complexity, supporting data-driven decisions, and connecting theory with practical security for cloud-native systems.

Keywords: MFA, Docker, Kubernetes, Fuzzy Logic, Multi-attribute risk assessment, Cloud computing

Received: 09 Jan 2025; Accepted: 16 Jun 2025.

Copyright: © 2025 Hersyah, Hossain, Taenaka and Kadobayashi. This is an open-access article distributed under the terms of the Creative Commons Attribution License (CC BY). The use, distribution or reproduction in other forums is permitted, provided the original author(s) or licensor are credited and that the original publication in this journal is cited, in accordance with accepted academic practice. No use, distribution or reproduction is permitted which does not comply with these terms.

* Correspondence: Mohammad Hafiz Hersyah, Nara Institute of Science and Technology (NAIST), Ikoma, Japan

Disclaimer: All claims expressed in this article are solely those of the authors and do not necessarily represent those of their affiliated organizations, or those of the publisher, the editors and the reviewers. Any product that may be evaluated in this article or claim that may be made by its manufacturer is not guaranteed or endorsed by the publisher.