Modern Network Security Architectures: A Critical Review of Networking and Cyber Defence Strategies

Uzoaru Godson Chetachi *

Department of Computer Science, Clifford University, Owerrinta, Abia State, Nigeria.

C. Nwasuka Stanley

Department of Computer Science, Clifford University, Owerrinta, Abia State, Nigeria.

Nwamuruamu Godswill Uchenna

Department of Computer Science, Clifford University, Owerrinta, Abia State, Nigeria.

Ikechuwku Miracle

Department of Computer Science, Clifford University, Owerrinta, Abia State, Nigeria.

Chinkere Evangel

Department of Computer Science, Clifford University, Owerrinta, Abia State, Nigeria.

Eke Emmanuel Amuche

Department of Computer Science, Clifford University, Owerrinta, Abia State, Nigeria.

Uju Chigozie

Department of Computer Science, Clifford University, Owerrinta, Abia State, Nigeria.

*Author to whom correspondence should be addressed.


Abstract

Network security architecture is being reshaped by cloud computing, remote and hybrid access, software-defined infrastructure, microservices, encryption, Internet of Things deployments and increasingly adaptive adversaries. These changes have weakened assumptions that a trusted internal network can be protected principally through perimeter controls, while simultaneously creating new dependencies on identity systems, policy engines, telemetry, orchestration and external security services. This critical narrative review evaluates how modern architectural families address these conditions and where their evidence remains incomplete. Literature published from 1 January 2010 to 27 June 2026 was considered, with earlier foundational studies retained where necessary. The synthesis integrates evidence on zero trust architecture, zero trust network access, microsegmentation, secure access service edge, software-defined networking, network function virtualisation, cloud-native and service-mesh security, intrusion and network detection, encrypted-traffic analytics, distributed denial-of-service defence, routing security, moving-target defence and cyber deception. The evidence supports a transition from location-based trust towards resource-, identity- and context-centred policy, but does not support treating any single architecture as a complete security solution. Zero trust is conceptually mature yet still has limited comparative evidence on enterprise outcomes and cost-effectiveness. Programmable networks improve enforcement agility and observability but concentrate control and introduce software and orchestration attack surfaces. Cloud-native controls strengthen service-to-service policy while shifting risk towards workload identity, certificate lifecycle, configuration correctness and supply-chain integrity. Machine-learning-based detection can augment analysis, particularly when payload visibility is constrained, but performance remains sensitive to dataset realism, protocol drift and deployment context. Resilience against denial-of-service, routing attacks and adaptive adversaries requires layered mechanisms extending beyond access control. The strongest architectural position is therefore compositional: identity assurance, least-privilege segmentation, programmable policy enforcement, trustworthy telemetry, resilient routing and availability controls, and carefully governed automation should reinforce one another without creating unexamined central points of failure.

Keywords: Zero trust, software-defined networking, network function virtualisation, secure access service edge, microsegmentation, cloud-native security, intrusion detection, cyber resilience


How to Cite

Chetachi, Uzoaru Godson, C. Nwasuka Stanley, Nwamuruamu Godswill Uchenna, Ikechuwku Miracle, Chinkere Evangel, Eke Emmanuel Amuche, and Uju Chigozie. 2026. “Modern Network Security Architectures: A Critical Review of Networking and Cyber Defence Strategies”. Asian Basic and Applied Research Journal 8 (1):722-46. https://doi.org/10.56557/abaarj/2026/v8i1253.

Downloads

Download data is not yet available.