DISTRIBUTED AI-ASSISTED RISK ASSESSMENT FOR ZERO-TRUST MICROSERVICES: A TAXONOMY AND CONCEPTUAL FRAMEWORK
Abstract
Microservice and cloud-native architectures have expanded the software attack surface at a pace that outstrips the adaptation of traditional risk assessment methods. Conventional vulnerability management remains centralized, static, severity-oriented, and disconnected from access control—characteristics that are ill-suited to distributed systems, where risk is shaped more by context and connectivity than by isolated weaknesses. This paper proposes a conceptual framework for distributed, AI-assisted risk assessment designed to address this gap. The framework synthesizes four bodies of literature—zero-trust architecture, microservice and cloud-native security, vulnerability analytics, and software risk management—and identifies precisely where each falls short. A six-dimensional taxonomy then structures the design space of distributed risk assessment, classifying approaches by signal source, granularity, analytical technique, risk model, zero-trust integration point, and temporality, and revealing a combination not yet explored by existing work. To fill this void, the paper introduces a four-layer framework: lightweight per-service agents collect multi-source evidence; AI-assisted analytics estimate exploit likelihood and detect anomalies; a graph-aware aggregation layer propagates risk across the service dependency graph; and an integration layer supplies a continuous per-service risk score to the zero-trust policy engine. An illustrative scenario demonstrates how a contextually significant but low-severity vulnerability would be surfaced and contained. As a conceptual contribution without experimental validation, the paper concludes by outlining key open challenges—data, robustness, performance, consistency, explainability, and evaluation—that must be addressed before the framework can be operationalized.