By: Md Sazzad Hossain, System Analyst, Kansas Bureau of Investigation | Cybersecurity Researcher
As identity-based cyberattacks surge across public institutions, researcher Md Sazzad Hossain’s AITIR Framework offers a technically rigorous, operationally validated answer built from the inside of government itself.
There is a quiet but consequential shift happening in the way governments are being attacked, and most people have no idea it is occurring.
The dramatic cyberattacks that dominate headlines- ransomware shutdowns, data exfiltration, and infrastructure sabotage- often obscure a subtler and, in many ways, more dangerous trend. Increasingly, the entry point for these attacks is not a vulnerability in software code or a misconfigured server.
This is the problem that researcher and government technology professional Md Sazzad Hossain has spent years working to solve.

The Moment the Perimeter Disappeared
For decades, cybersecurity operated on a simple premise. Build a strong enough wall around your systems, and you are safe. Firewalls, intrusion detection systems, and network monitoring tools were designed around this logic, the assumption that the threat came from outside and that the inside was, by definition, trustworthy.
That assumption no longer holds.
“Government organizations increasingly depend on digital identities as the foundation for accessing systems, services, and information. As threat actors continue targeting identity systems, cybersecurity strategies must evolve to address these risks more effectively.” — Md Sazzad Hossain
That gap between available tools and actual threats is what led him and his research collaborator Kiran Kumar Parvatha Reddy to develop the AI-Assisted Adaptive Threat Intelligence and Response (AITIR) Framework.
Six Layers Between a Credential and a Catastrophe
Published in the International Journal on Science and Technology, the AITIR paper, “AI-Enhanced Identity Threat Detection and Automated Response: An AITIR Framework for Optimized Cybersecurity Operations,” is not a theoretical exercise.
AITIR is built as a six-layer pipeline. Think of it as a highly automated assembly line, except instead of manufacturing a product, it processes the digital exhaust that every identity-related activity leaves behind and turns it into a security decision.
The raw material feeding this pipeline comes from sources that most government organizations already collect but rarely integrate effectively. Active Directory logs record who logged in, when, and from where. Multi-factor authentication (MFA) records flag unusual verification patterns. Privileged access management (PAM) data tracks who accessed sensitive systems, and VPN session logs reveal remote access behavior.
That data is then analyzed by three distinct artificial intelligence engines working in concert. An Isolation Forest algorithm scans for anomalies without needing to know what an attack looks like in advance. A Long Short-Term Memory (LSTM) neural network adds a temporal dimension, detecting attack patterns that develop over hours or days. The outputs are merged into a single metric, the Identity Risk Score (IRS).
Numbers That Make the Case

Frameworks live or die by their results. AITIR’s empirical performance, validated against real-world identity log datasets, is difficult to dismiss.

For context, false positives are not a minor inconvenience in a security operations center. Every false alert consumes analyst time, erodes confidence in automated systems, and creates the kind of alert fatigue that causes real threats to be dismissed. A 41% reduction is not a marginal gain. It is the difference between a team that can keep pace with its threat environment and one that is perpetually overwhelmed.
The Human Question
There is an understandable anxiety within cybersecurity circles, and in government institutions more broadly, about the role of artificial intelligence in high-stakes decision-making.
Hossain is direct about where AITIR stands on this question. The framework is not designed to replace human judgment. It is designed to give human analysts better information, faster, so that their judgment is applied where it matters most.
“Research becomes more valuable when it is informed by operational realities. Understanding how organisations actually manage cybersecurity challenges can help create approaches that are both practical and adaptable.” — Md Sazzad Hossain
Why Government Cannot Wait
The AITIR framework is one part of a broader, more urgent conversation that governments across the world are only beginning to have seriously. India’s Digital India initiative, the United States federal government’s zero-trust architecture mandates, and the European Union’s NIS2 directive all converge on a common recognition. Identity is infrastructure.
The Road Ahead
Hossain continues to expand the AITIR research program, engaging with peer-review activities across cybersecurity journals and contributing to scholarly discussions on topics ranging from post-quantum cryptography to AI governance in security operations.
The work reflects a broader maturation in how the cybersecurity field thinks about artificial intelligence, less as a silver bullet and more as a force multiplier for human expertise.
“Cybersecurity is no longer only about building stronger defenses. It is also about building systems that can adapt, recover, and continue supporting essential services in the face of evolving threats.” — Md Sazzad Hossain
About the Author
Md Sazzad Hossain is a System Analyst and cybersecurity researcher at the Kansas Bureau of Investigation, United States. He is a co-developer of the AITIR Framework and a published researcher in AI-assisted identity security, government cybersecurity, and cyber resilience. He serves as a peer reviewer for multiple international cybersecurity journals.
Research References
[1] AI-Enhanced Identity Threat Detection and Automated Response (International Journal on Science and Technology)
[2] AI-Assisted Identity and Access Threat Detection Using the AITIR Framework (Journal of Computer Science and Technology Studies)











