This paper proposes a graph-based method for forming corporate-network security domains from object-level risk attributes. Importance, vulnerability, attack probability, and estimated loss are combined into a continuous risk score and mapped to discrete security levels. Objects with equal levels are grouped into disjoint domains, mixed-level service conflicts are resolved, and boundary controls are inserted on inter-domain edges. A Python prototype implements the scoring, graph partitioning, and boundary-insertion sequence. The method is evaluated on a synthetic 150-node corporate topology with 5,000 daily flows. Relative to a flat baseline, the reported scenario reduces average blast radius from 100% to 18.5% and directed attack paths from 22,350 to 1,240. Unlike VLANs, which provide logical network separation, Zero Trust, which applies per-request policy decisions, and SDN, which provides programmable forwarding control, the proposed method computes risk-based domain membership and boundary locations. It is therefore complementary to these enforcement approaches. The study is a simulation and prototype evaluation rather than a production-network deployment.
IEEE Std 802.1Q-2022, IEEE Standard for Local and Metropolitan Area Networks-Bridges and Bridged Networks. IEEE, 2022.
S. Rose, O. Borchert, S. Mitchell, and S. Connelly, Zero Trust Architecture, NIST Special Publication 800-207. Gaithersburg, MD, USA: National Institute of Standards and Technology, 2020, [Online]. Available: https://doi.org/10.6028/NIST.SP.800-207.
Open Networking Foundation, SDN Architecture 1.1, ONF TR-521, Feb. 2016.
FIRST, Common Vulnerability Scoring System Version 4.0: Specification Document, 2023.
J. Zhang, W. Wang, and E. Zio, “Study on the application of graph theory algorithms and attack graphs in cybersecurity assessment,” in Proc. 2023 7th International Conference on System Reliability and Safety (ICSRS), Bologna, Italy, pp. 558-564, 2023, [Online]. Available: https://doi.org/10.1109/ICSRS59833.2023.10381005.
L. Bradatsch and F. Kargl, “Integration of security service functions into network-level access control,” IEEE Access, vol. 12, pp. 197783-197815, 2024, [Online]. Available: https://doi.org/10.1109/ACCESS.2024.3522575.
S. Sayfullaev, D. Valikulova, and K. Sabirov, “Modern intelligent security analysis systems for corporate networks,” in Proc. 2024 5th International Conference on Image Processing and Capsule Networks (ICIPCN), Dhulikhel, Nepal, pp. 717-719, 2024, [Online]. Available: https://doi.org/10.1109/ICIPCN63822.2024.00124.
M. M. Talipov, “Computational modeling and analysis of mechanical power consumption in train assemblers’ work,” Proceedings of International Conference on Applied Innovation in IT, vol. 13, no. 2, pp. 419-426, 2025, [Online]. Available: https://doi.org/10.25673/120513.
R. Salmorbekova and M. Talipov, “Digital risk matrix and safety management workflow for airport infrastructure in developing countries: a data-driven prioritization approach,” Vibroengineering Procedia, vol. 62, pp. 653-661, Jun. 2026, [Online]. Available: https://doi.org/10.21595/vp.2026.26121.
Y. Cao, S. R. Pokhrel, Y. Zhu, et al., “Automation and orchestration of zero trust architecture: Potential solutions and challenges,” Machine Intelligence Research, vol. 21, pp. 294-317, 2024, [Online]. Available: https://doi.org/10.1007/s11633-023-1456-2.
H. Moudoud, Z. Abou El Houda, and B. Brik, “Zero trust security architecture for 6G open radio access networks (O-RAN),” IEEE Networking Letters, 2024, [Online]. Available: https://doi.org/10.1109/LNET.2024.3514357.
V. Jain, D. Ather, A. B. Abdul Hamid, R. R. Sharma, G. Talipova, and G. Manteghi, “Secure Arduino-based LiFi communication for IoT sensor networks,” in Proc. 2025 Optical Communication, Photonics, Telecommunications, and Intelligent Machine Applications (OPTIMA), Tashkent, Uzbekistan, pp. 189-194, 2025, [Online]. Available: https://doi.org/10.1109/OPTIMA67660.2025.11380401.