Zero Trust Network Access (ZTNA) has emerged as a fundamental paradigm for securing cloud-native and distributed computing environments. However, existing ZTNA implementations remain largely limited by static policy enforcement and opaque machine-learning-based anomaly detection mechanisms, which often lack contextual adaptability, policy awareness, and interpretable decision-making capabilities. These limitations create significant challenges in dynamic multi-cloud environments where access behavior continuously evolves and security decisions must be both accurate and explainable. To address these challenges, this study proposes Cognitive ZTNA framework, a unified neuro-symbolic trust enforcement framework that integrates transformer-based behavioral trust modeling with ontology-guided symbolic reasoning. The proposed architecture enables continuous trust evaluation by combining behavioral access patterns with explicit policy semantics through a hybrid trust fusion mechanism. This design allows the system to capture long-range behavioral dependencies while maintaining policy-compliant and interpretable access control decisions. The framework is evaluated using the CloudZT-Bench-2025 dataset, comprising 4.2 million cross-platform access events derived from enterprise security telemetry, AWS CloudTrail logs, and simulated adversarial scenarios. Experimental results demonstrate that Cognitive ZTNA achieves Precision = 0.96, Recall = 0.93, and F1-score = 0.95, significantly outperforming rule-based and machine-learning baselines while reducing the false positive rate to 0.03. In addition, the system maintains real-time feasibility with an average decision latency of 24 ms and explanation latency below 5 ms, while achieving 92% analyst-rated explanation sufficiency. These findings demonstrate that integrating behavioral intelligence with symbolic policy reasoning enables adaptive, interpretable, and policy-aware Zero Trust enforcement. The proposed framework therefore provides a practical foundation for next-generation ZTNA systems capable of supporting secure, transparent, and context-aware access control in modern cloud environments.
Ahmed Alzahrani (Fri,) studied this question.