An Adaptive Multi-Factor Authentication Framework for Enhancing User-Centric Security in Dynamic Threat Environments
Keywords:
Adaptive authentication, MFA, cybersecurity, risk-based authentication, identity managementAbstract
Broken and static authentication mechanisms remain a leading cause of web-application breaches, as attackers exploit predictable recovery questions, credential stuffing, and session hijacking. Most deployed Multi-Factor Authentication (MFA) systems apply the same fixed burden to every user regardless of context, weakening protection against evolving threats while creating unnecessary friction for legitimate users. This paper proposes an Adaptive Multi-Factor Authentication (AMFA) framework combining contextual risk scoring with user-defined, high-entropy fallback questions to strengthen account security while preserving usability. The study followed Design Science Research, drawing requirements from OWASP ASVS, the NIST Cybersecurity Framework 2.0, and FAIR risk principles. The architecture comprises four cooperating services, a Context Collector, a Risk Engine, an Authentication Factor Manager, and a User-Defined Question Store, which evaluate device trust, geolocation, behavior, time-of-day, and network reputation to dynamically select authentication factors per session. Because no production deployment yet exists, the framework was validated through structured expert review and prospective-user assessment rather than live traffic. Twenty security professionals evaluated the design against OWASP ASVS v4.0.3 controls and reported 94 percent compliance, with a median defensive-strength rating of 4.6 out of 5. A separate cohort of prospective users assessed interface mockups using the System Usability Scale, yielding a score of 88 out of 100. A scenario-based FAIR analysis suggests the approach could reduce account-recovery-related breaches by roughly 60 percent relative to static MFA. These findings indicate that adaptive, context-aware authentication can meaningfully improve security posture without excessive usability costs, motivating future work on prototype deployment and real-world validation.