Open Access

Risk-Based Security Assessment of Federated Authentication Systems: STRIDE Analysis of Identity, Session, and Access Threats

4 Department of Data Science and Intelligent Computing, Institute of Advanced Computational Studies, Colombo, Sri Lanka
4 Department of Machine Learning and Data Analytics, Institute of Advanced Computational Studies, Kandy, Sri Lanka

Abstract

Federated authentication systems have become an important architectural mechanism for enabling users to access multiple services through shared identity infrastructure. Their security, however, depends on the integrity of identity assertions, authentication exchanges, session-management mechanisms, and authorization decisions distributed across multiple trust domains. This paper presents a risk-based security assessment of federated authentication systems using the STRIDE threat-modeling framework, with particular emphasis on identity, session, and access-related threats. The methodology combines system decomposition, trust-boundary analysis, STRIDE categorization, risk prioritization, and analytical interpretation of attack surfaces. A conceptual risk model is developed in which threats are assessed according to their potential effect on identity integrity, confidentiality, availability, authentication assurance, and authorization correctness. The study further considers how machine-learning and statistical modeling concepts can support systematic threat prioritization and anomaly-oriented analysis. Existing methodological foundations concerning deep learning, statistical modeling, nonlinear optimization, and machine-learning estimation provide theoretical support for the analytical treatment of complex security data (Alzubaidi et al., 2021; Coleman and Li, 1994; Farrell et al., 2021). The assessment indicates that identity spoofing, authentication-message tampering, session compromise, privilege escalation, and denial-of-service conditions represent particularly significant risk classes in federated environments. The analysis demonstrates that STRIDE is most effective when combined with risk-based prioritization rather than being used as a simple checklist. The resulting framework provides a structured basis for identifying critical trust-boundary failures and prioritizing defensive controls across federated authentication architectures.

How to Cite

Nuwan Perera, & Ishara Fernando. (2026). Risk-Based Security Assessment of Federated Authentication Systems: STRIDE Analysis of Identity, Session, and Access Threats. Frontiers in Emerging Computer Science and Information Technology, 3(09), 01–06. https://doi.org/10.64917/fecsit/Volume03Issue09-01

References

Alzubaidi L, Zhang J, Humaidi AJ, et al. (2021). Review of deep learning: Concepts, CNN architectures, challenges, applications, future directions. Journal of Big Data, 8(1): 53.
Coleman TF, Li Y (1994). On the convergence of reflective Newton methods for large-scale nonlinear minimization subject to bounds. Mathematical Programming, 67(2): 189–224.
Fan J (2018). Local Polynomial Modelling and Its Applications, Monographs on Statistics and Applied Probability 66. Routledge.
Farrell MH, Liang T, Misra S (2021). Deep neural networks for estimation and inference. Econometrica, 89(1): 181–213.
Friedman JH (1991). Multivariate adaptive regression splines. The Annals of Statistics, 19(1): 1–67.
Friedman JH, Tibshirani R, Hastie T (2001). The Elements of Statistical Learning: Data Mining, Inference, and Prediction, 1st ed. Springer Series in Statistics. Springer, New York.
Ganapathy, S. K (2024). Threat Modeling for Federated SSO and MFA Systems: STRIDE-Based Analysis of Attack Vectors. International Journal of Data Science and Machine Learning, 4(02), 55-73. https://www.academicpublishers.org/journals/index.php/ijdsml/article/view/stride-analysis-sso-mfa
Goodfellow I, Bengio Y, Courville A (2016). Deep Learning. MIT Press.