Securing Trust: Rule-Based Defense Against On/Off and Collusion Attacks in Cloud Environments
Qais Al-Na’amneh ;
Mahmoud Aljawarneh ;
Ahmad Saleh Alhazaimeh ;
Rahaf Hazaymih ;
Shahid Munir Shah ;
Walid Dhifallah
Published: 2025/12/01
Abstract
The pervasive adoption of cloud computing, underscored by its distributed, multi-tenant characteristics, introduces intricate vulnerabilities concerning trust assurance. Malicious entities increasingly deploy sophisticated stratagems, such as on/off behavioral subterfuge and orchestrated collusion, to subvert conventional trust assessment mechanisms. This manuscript introduces a Hierarchical Rule-Based Trust Orchestration System (HRTOS), a non-learning, deterministically governed architectural framework designed for the proactive identification and mitigation of these insidious threats within federated cloud environments. HRTOS operates through a synergistic ensemble of modules dedicated to multi-vector behavioral fingerprinting, contextual anomaly evaluation, feedback integrity validation, and collusion pattern grammar analysis. The system’s core philosophy emphasizes operational transparency, imposing minimal computational burden while exhibiting acute sensitivity to nuanced deviations from normative interaction patterns. Rigorous simulations employing diverse synthetic user archetypes—spanning consistent integrity, strategic deception, and coordinated malevolence—demonstrate HRTOS’s pronounced capability to accurately discern legitimate activities from complex reputation manipulation endeavors. Conventional trust paradigms, frequently reliant on computationally intensive machine learning or opaque probabilistic models, often falter when confronted by adaptive adversaries exploiting systemic latencies, sparse data conditions, or the inherent ”black-box” nature of such models. HRTOS circumvents these limitations by employing a layered, context-aware rule engine that processes interaction telemetry and feedback metadata in near real-time. Abrupt behavioral transitions are identified via a multi-faceted deviation index; anomalous feedback is systematically de-weighted through source credibility and content plausibility checks; collusive engagements are surfaced by analyzing reciprocity dynamics and group behavioral coherence. Trust state adjudication is effectuated through deterministic rule sets, fostering auditable enforcement and low-latency response. The presented evaluations, encompassing varied attack vectors including sophisticated on/off attacks and multi-entity collusion schemes, affirm the model’s high fidelity in threat differentiation, its negligible false positive incidence, and its inherent interpretability, rendering HRTOS exceptionally suitable for securing dynamic, federated cloud ecosystems where accountability, efficiency, and proactive threat neutralization are paramount.
Keywords
How to Cite the Article
Al-Na’amneh, Q., Aljawarneh, M., Alhazaimeh, A. S., Hazaymih, R., & Shah, S. M. (2025). Securing Trust: Rule-Based Defense Against On/Off and Collusion Attacks in Cloud Environments. STAP Journal of Security Risk Management, 2025(1), 85–114. https://doi.org/10.63180/jsrm.thestap.2025.1.5
Securing Trust: Rule-Based Defense Against On/Off and Collusion Attacks in Cloud Environments is licensed under CC BY 4.0
References
- Soleymani, M., Abapour, N., Taghizadeh, E., Siadat, S., & Karkehabadi, R. (2021). Fuzzy rule-based trust management model for the security of cloud computing. Mathematical Problems in Engineering, 2021, Article 6629449.
- Chahal, R. K., & Singh, S. (2017). Fuzzy rule-based expert system for determining trustworthiness of cloud service providers. International Journal of Fuzzy Systems, 19, 338–354.
- Rathi, P., Ahuja, H., & Pandey, K. (2017). Rule-based trust evaluation using fuzzy logic in cloud computing. In Proceedings of the 2017 6th International Conference on Reliability, Infocom Technologies and Optimization (ICRITO) (pp. 510–514). IEEE.
- Loonkar, S., Taneja, N., & Beemkumar, N. (2024). Fuzzy rule-based trust management for cloud security. In Proceedings of the 2024 1st International Conference on Sustainable Computing and Integrated Communication in Changing Landscape of AI (ICSCAI) (pp. 1–12). IEEE.
- Yang, P., Xiong, N., & Ren, J. (2020). Data security and privacy protection for cloud storage: A survey. Ieee Access, 8, 131723-131740.
- Kesarwani, A., & Khilar, P. M. (2022). Development of trust-based access control models using fuzzy logic in cloud computing. Journal of King Saud University – Computer and Information Sciences, 34(5), 1958–1967.
- Islam, M. S., Ozdayi, M. S., Khan, L., & Kantarcioglu, M. (2020). Secure IoT data analytics in cloud via Intel SGX. In Proceedings of the 2020 IEEE 13th International Conference on Cloud Computing (CLOUD) (pp. 43–52). IEEE.
- Veena, C., Ramalakshmi, S., Bhoopathy, V., Bhosale, M. D., Magadum, C. G., & Abirami, S. K. (2022). Effective intrusion detection and classification using fuzzy rule-based classifier in cloud environment. In Proceedings of the 2022 International Conference on Automation, Computing and Renewable Systems (ICACRS) (pp. 497–502). IEEE.
- Wang, Y., & Yang, X. (2025, April). Research on enhancing cloud computing network security using artificial intelligence algorithms. In 2025 International Conference on Sensor-Cloud and Edge Computing System (SCECS) (pp. 237-244). IEEE. https://arxiv.org/abs/2502.17801
- Alturfi, S. M., Muhsen, D. K., Mohammed, M. A., Aziz, I. T., & Aljshamee, M. (2021). A combination techniques of intrusion prevention and detection for cloud computing. Journal of Physics: Conference Series, 1804, Article 012121.
- Al-Na'amneh, Q., Almomani, A., Nasayreh, A., Nahar, K. M. O., Gharaibeh, H., Al Mamlook, R. E., & Alauthman, M. (2024). Next generation image watermarking via combined DWT-SVD technique. In Proceedings of the 2024 2nd International Conference on Cyber Resilience (ICCR) (pp. 1–10). IEEE.
- Jaradat, A. S., Nasayreh, A., Al-Na'amneh, Q., Gharaibeh, H., & Al Mamlook, R. E. (2023). Genetic optimization techniques for enhancing web attacks classification in machine learning. In Proceedings of the 2023 IEEE International Conference on Dependable, Autonomic and Secure Computing, Pervasive Intelligence and Computing, Cloud and Big Data Computing, and Cyber Science and Technology Congress (DASC/PiCom/CBDCom/CyberSciTech) (pp. 130–136). IEEE.
- Abu Laila, D., Al-Na'amneh, Q., Aljaidi, M., Nasayreh, A. N., Gharaibeh, H., Al Mamlook, R. E., & Alshammari, M. (2024). Simulation of routing protocols for jamming attacks in mobile ad-hoc networks. In Risk Assessment and Countermeasures for Cybersecurity (pp. 235–252). IGI Global.
- Murad, S. A., Muzahid, A. J. M., Azmi, Z. R. M., Hoque, M. I., & Kowsher, M. (2022). A review on job scheduling technique in cloud computing and priority rule-based intelligent framework. Journal of King Saud University – Computer and Information Sciences, 34(6), 2309–2331.
- Nasir, H., Ayaz, A., Nizamani, S., Siraj, S., Iqbal, S., & Abid, M. K. (2024). Cloud computing security via intelligent intrusion detection mechanisms. International Journal of Information Systems and Computer Technologies, 3(1), 84–92.
- Parisa, S. K., & Banerjee, S. (2024). AI-enabled cloud security solutions: A comparative review of traditional vs. next-generation approaches. International Journal of Statistical Computation and Simulation, 16(1).
- Rani, U., Dalal, S., & Kumar, J. (2018). Optimizing performance of fuzzy decision support system with multiple parameter dependency for cloud provider evaluation. International Journal of Engineering & Technology, 7(1.2), 61–65.
- John, J., & Singh, K. J. (2024). Trust value evaluation of cloud service providers using fuzzy inference-based analytical process. Scientific Reports, 14, Article 18028.
- Plazas Olaya, M. K., Vergara Tejada, J. A., & Aedo Cobo, J. E. (2024). Securing Microservices‐Based IoT Networks: Real‐Time Anomaly Detection Using Machine Learning. Journal Of Computer Networks And Communications, 2024(1), 9281529.
- Mehata, M. (2025). Dynamic zero trust access control: Fortifying security in mobile-cloud environment (Master's thesis). Youngstown State University.
- Parkhomenko, I., Myrutenko, L., Ohiievych, R., & Savonik, M. (2024). Using Zero Trust Principles for Detecting Authorization Attacks in Cloud Environments. In IT&I (pp. 181-195).
- Mondal, H. S., Hasan, M. T., Hossain, M. B., Rahaman, M. E., & Hasan, R. (2017). Enhancing secure cloud computing environment by detecting DDoS attack using fuzzy logic. In Proceedings of the 2017 3rd International Conference on Electrical Information and Communication Technology (EICT) (pp. 1–4). IEEE.
- Chaudhary, D., Verma, S. K., Shrimal, V. M., Madala, R., & Baliyan, R. (2024, August). Ai-based methods to detect and counter cyber threats in cloud environments to strengthen cloud security. In 2024 International conference on electrical electronics and computing technologies (ICEECT) (Vol. 1, pp. 1-6). IEEE.
- Mandal, S., Khan, D. A., & Jain, S. (2021). Cloud-based zero trust access control policy: An approach to support work-from-home driven by the COVID-19 pandemic. New Generation Computing, 39(3), 599–622.
- Madanan, M., Patel, P., Agrawal, P., Mudholkar, P., Mudholkar, M., & Jaganraja, V. (2024, September). Security challenges in multi-cloud environments: Solutions and best practices. In 2024 7th International Conference on Contemporary Computing and Informatics (IC3I) (Vol. 7, pp. 1608-1614). IEEE.
- Shen, Q., & Shen, Y. (2024). Endpoint security reinforcement via integrated zero-trust systems: A collaborative approach. Computers & Security, 136, Article 103537.
- Modi, C. N., & Acha, K. (2017). Virtualization layer security challenges and intrusion detection/prevention systems in cloud computing: A comprehensive review. The Journal of Supercomputing, 73(3), 1192–1234.
- Golightly, L., Modesti, P., Garcia, R., & Chang, V. (2023). Securing distributed systems: A survey on access control techniques for cloud, blockchain, IoT, and SDN. Cyber Security and Applications, 1, Article 100015.
- Hatef, M. A., Shaker, V., Jabbarpour, M. R., Jung, J., & Zarrabi, H. (2018). HIDCC: A hybrid intrusion detection approach in cloud computing. Concurrency and Computation: Practice and Experience, 30(3), e4171.
- Bhajantri, L. B., & Mujawar, T. (2019). A survey of cloud computing security challenges, issues and their countermeasures. In Proceedings of the 2019 Third International Conference on I-SMAC (IoT in Social, Mobile, Analytics and Cloud) (pp. 376–380). IEEE.
- Sehgal, N. K., Bhatt, P. C. P., & Acken, J. M. (2022). Future trends in cloud computing. In Cloud Computing with Security and Scalability: Concepts and Practices (pp. 289–317). Springer.
- Aslan, O., Ozkan-Okay, M., & Gupta, D. (2021). Intelligent behavior-based malware detection system on cloud computing environment. IEEE Access, 9, 83252–83271.
- Samuel, J. K., Jacob, M. T., Roy, M., Sayoojya, P. M., & Joy, A. R. (2023). Intelligent malware detection system based on behavior analysis in cloud computing environment. In Proceedings of the 2023 International Conference on Circuit, Power and Computing Technologies (ICCPCT) (pp. 109–113). IEEE.
- Khan, M. A., Khan, S. M., & Subramaniam, S. K. (2023). Secured dynamic request scheduling and optimal CSP selection for analyzing cloud service performance using intelligent approaches. IEEE Access, 11, 140914–140933.
- Chiregi, M., & Navimipour, N. J. (2017). A comprehensive study of the trust evaluation mechanisms in cloud computing. Journal of Service Science Research, 9, 1–30.
- Arunkumar, M., & Kumar, K. A. (2022). Malicious attack detection approach in cloud computing using machine learning techniques. Soft Computing, 26(23), 13097–13107.
- Abhinav, B. V., Abhirup, M. V. N. S., Adithya, D. S., & Clara Kanmani, A. (2025, April). Dynamic Threat Detection and Mitigation Using AI-Infused Firewalls. In 2025 13th International Symposium on Digital Forensics and Security (ISDFS) (pp. 1-5). IEEE.
- Chokkanathan, K., Karpagavalli, S. M., Priyanka, G., Vanitha, K., Anitha, K., & Shenbagavalli, P. (2024, November). Ai-driven zero trust architecture: Enhancing cyber-security resilience. In 2024 8th International Conference on Computational System and Information Technology for Sustainable Solutions (CSITSS) (pp. 1-6). IEEE.
- Hasani Zade, B. M., Mansouri, N., & Javidi, M. M. (2021). SAEA: A security-aware and energy-aware task scheduling strategy by parallel squirrel search algorithm in cloud environment. Expert Systems with Applications, 176, Article 114915.
- Alsahaim, S., Almaiah, M. A., & Sulaiman, R. B. (2023). Security threats in mobile phones: Challenges, countermeasures, and the importance of user awareness. International Journal of Cybersecurity Engineering and Innovation, 2023(1).
- Ayo, F. E., Folorunso, S. O., Abayomi-Alli, A. A., Adekunle, A. O., & Awotunde, J. B. (2020). Network intrusion detection based on deep learning model optimized with rule-based hybrid feature selection. Information Security Journal: A Global Perspective, 29(6), 267–283.
- Chenthara, S., Ahmed, K., Wang, H., & Whittaker, F. (2019). Security and privacy-preserving challenges of e-health solutions in cloud computing. IEEE Access, 7, 74361–74382.
- Adee, R., & Mouratidis, H. (2022). A dynamic four-step data security model for data in cloud computing based on cryptography and steganography. Sensors, 22(3), 1109.
- Nassif, A. B., Talib, M. A., Nasir, Q., Albadani, H., & Dakalbab, F. M. (2021). Machine learning for cloud security: a systematic review. IEEE Access, 9, 20717-20735.
- Priya, S., & Ponmagal, R. S. (2023). Trust-based reputation framework for data center security in cloud computing environment. In Proceedings of the 2023 7th International Conference on Computing Methodologies and Communication (ICCMC) (pp. 1041–1047). IEEE.
- Mercado, R. F. (2022). Identifying the advantages of zero-trust architecture in the cloud environment (Master's thesis). Utica University.
- Alzoubi, Y. I., Mishra, A., & Topcu, A. E. (2024). Research trends in deep learning and machine learning for cloud computing security. Artificial intelligence review, 57(5), 132.
- Butt, U. A., Mehmood, M., Shah, S. B. H., Amin, R., Shaukat, M. W., Raza, S. M., ... & Piran, M. J. (2020). A review of machine learning algorithms for cloud computing security. Electronics, 9(9), 1379.
- Alghareeb, M. S., Almaiah, M. A., & Badr, Y. (2024). Cyber security threats in wireless LAN: A literature review. International Journal of Cybersecurity Engineering and Innovation, 2024(1).
- Attou, H., Guezzaz, A., Benkirane, S., Azrour, M., & Farhaoui, Y. (2023). Cloud-based intrusion detection approach using machine learning techniques. Big Data Mining and Analytics, 6(3), 311-320.
- Polamarasetti, A. (2024, November). Role of Artificial Intelligence and Machine Learning to Enhancing Cloud Security. In 2024 International Conference on Intelligent Computing and Emerging Communication Technologies (ICEC) (pp. 1-6). IEEE.