Improving Zero Trust Architecture with Machine Learning: Automatic Threat Detection using Network Traffic Analysis
Vibhas Mohan Zanpure · 2025
Artificial intelligence (AI) and machine learning are becoming more and more important in enhancing threat detection, response, and proactive defense as cybersecurity quickly changes. The AI Shield and Red AI frameworks are two well-known systems that use ML to tackle Cyber Threat Intelligence (CTI) issues. In this paper, machine learning-based methodology is proposed to enhance Zero Trust Architecture (ZTA) through intelligent and automated threat detection leveraging network traffic analysis. Three classification models, Logistic Regression (LR), Random Forest (RF), and XGBoost (XGB), were implemented and evaluated based on accuracy, precision, recall, and F1score. RF achieved the best performance with 98.64% accuracy and a 97.67% F1-score, followed by XGB with 98.19% accuracy and 96.92% F1-score. LR obtained 94.57% accuracy, 91.43% F1-score, and the highest recall of 98.46%. The comparative analysis simply validates the authenticity of ensemble models, especially RF, capable of providing stable and satisfactory threat identification in the ZTA context. The results thus reveal how effective the ensemble approach of the method is in eliminating false positives and enhancing the efficiency of threat detection within the context of ZTA frameworks.