π A definitive curated index, benchmark, and architectural guide to enterprise Risk-Based Authentication (RBA), Adaptive Multi-Factor Authentication (MFA), Continuous Adaptive Trust (CAEP/SSE), and Identity Threat Detection & Response (ITDR) β featuring verified commercial SaaS pricing, free tier limits, market size analysis, and battle-tested open-source alternatives sorted by GitHub_Stars.
risk-based-authentication β’ adaptive-mfa β’ step-up-authentication β’ continuous-authentication β’ zero-trust-identity β’ identity-threat-detection β’ itdr β’ behavioral-biometrics β’ device-fingerprinting β’ conditional-access β’ passkeys β’ fido2 β’ keycloak β’ authentik β’ open-policy-agent
- π§ What Is Risk-Based Authentication?
- βοΈ Core RBA Capabilities
- π’ SaaS / Hosted Platforms
- π Open-Source
- β Top Open-Source Projects Table (Sorted by Stars)
- π¦ Open-Source RBA Platforms
- π Open-Source Identity and MFA
- β‘ Risk Engines and Policy Engines
- π§ Behavioral and Continuous Authentication
- π± Device and Fingerprinting
- π Threat Intelligence and IP Reputation
- π¨ Fraud and Anomaly Detection
- π Policy and Access Control
- π Authentication Protocols
- π Security Analytics and SIEM
- πΊοΈ Commercial β Open-Source Mapping
- ποΈ RBA Architecture
- π Reference Architecture
- π Adaptive MFA Flow
- π² Risk Scoring
- β‘ Continuous Authentication
- π‘οΈ Zero Trust Architecture
- π§© Open-Source RBA Stack
- π Capability Matrix
- π οΈ Recommended Open-Source Stacks
- βοΈ What Open Source Can Replace
β οΈ What Open Source Cannot Replace Automatically- π Security Considerations
- π Licensing Considerations
- π― Project Selection Guide
- π Top Open-Source Shortlist
- π Star History
- π Disclaimer
Risk-Based Authentication is an adaptive authentication model in which the authentication requirement changes according to the estimated risk of an access request.
Typical inputs include:
- Username / identity
- Device identity
- Device posture
- Browser characteristics
- IP address
- ASN
- IP reputation
- VPN / Tor / proxy detection
- Geolocation
- Geo-velocity
- Time of day
- Login frequency
- Historical behavior
- Authentication history
- Failed-login patterns
- Credential compromise
- Threat intelligence
- Application sensitivity
- User role
- Network trust
- Session age
- Transaction context
- Behavioral biometrics
- Anomaly detection
- Previous MFA results
The resulting risk can determine whether the system:
ALLOW
CHALLENGE
STEP-UP MFA
REAUTHENTICATE
RESTRICT
BLOCK
Microsoft Entra ID Protection, for example, calculates user and sign-in risk and can feed those signals into Conditional Access policies that require MFA, remediation, reauthentication, or blocking.
| Capability | Description |
|---|---|
| Risk scoring | Calculate authentication risk |
| Adaptive MFA | Increase authentication requirements when risk rises |
| Step-up authentication | Require additional factors only when necessary |
| Device intelligence | Identify trusted/untrusted devices |
| IP intelligence | Detect malicious or suspicious IP addresses |
| Geolocation | Analyze geographic context |
| Impossible travel | Detect unrealistic geographic movement |
| Behavioral analytics | Compare current behavior with historical behavior |
| Threat intelligence | Incorporate external security intelligence |
| Credential intelligence | Detect leaked or compromised credentials |
| Session risk | Continuously evaluate an authenticated session |
| Continuous authentication | Revalidate identity after initial login |
| Policy engine | Translate risk into access decisions |
| Risk remediation | Allow users to recover from risky authentication |
| Risk-based passwordless | Combine strong authentication with risk |
| Transaction risk | Increase authentication for sensitive operations |
| Identity risk | Evaluate the probability that an identity is compromised |
| Workload risk | Evaluate non-human/service identities |
| SIEM integration | Export risk events |
| API integration | Allow applications to consume risk decisions |
This section intentionally remains separate from the Open-Source section. Not every product below is strictly SaaS-only; the category includes commercial cloud, hosted, enterprise, and hybrid RBA / Identity Threat Protection platforms.
π Market Size & Landscape Dynamics: The global Risk-Based Authentication (RBA) and Adaptive Authentication market is estimated at $4.5Bβ$6.0B (projected to exceed $18B+ by 2032 growing at a CAGR of ~20.5%). The sector is moderately fragmented: while cloud platform titans (Microsoft, Cisco, IBM) dominate core enterprise directory infrastructure and baseline MFA, specialized identity threat protection and CIAM innovators (Okta, Ping Identity, Silverfort, CrowdStrike, Cloudflare) capture substantial enterprise workload share across hybrid Active Directory, zero-trust network access, and legacy protocols, preventing a single winner-take-all monopoly.
The table below lists leading SaaS and commercial RBA platforms sorted in descending order by company valuation, market capitalization, or annual revenue.
| Platform π’ | Description & Primary Focus π | Company Size / Valuation π° | Starting Pricing π·οΈ | Free Tier Limit / Free Trial Details π |
|---|---|---|---|---|
| Microsoft Entra ID Protection | Identity security and risk engine detecting user and sign-in risks, automating risk-based Conditional Access, detecting password spray and token theft, and enforcing step-up MFA remediation. | $3.10T Market Cap (Microsoft: ~$245B+ Rev) |
Included in Entra ID P2 at $9.00/user/month (or Microsoft Entra Suite at $12.00/user/month, or bundled in Microsoft 365 E5 at $57.00/user/month; billed annually). | Free forever for Microsoft Entra ID Free (basic directory & baseline MFA; excludes risk-based Conditional Access); 30-day free trial of Entra ID P2 for up to 100 users. |
| Microsoft Defender for Identity | Active Directory domain-sensor security monitoring that detects compromised identities, lateral movement paths, pass-the-hash attacks, and feeds real-time risk telemetry into Entra ID Protection. | $3.10T Market Cap (Microsoft: ~$245B+ Rev) |
Standalone license starts at $5.50/user/month (or included in Enterprise Mobility + Security E5 at $16.40/user/month, or Microsoft 365 E5 at $57.00/user/month; billed annually). | 30-day free trial via Microsoft 365 E5 or Microsoft Defender XDR trial (includes up to 25 user licenses with full Active Directory sensor deployment and threat telemetry; no perpetual free tier). |
| IBM Verify | Enterprise identity platform featuring AI-powered adaptive access, continuous risk scoring, contextual step-up MFA, passwordless login, and hybrid identity governance. | $210B Market Cap (IBM: ~$62B+ Rev) |
Modular SaaS pricing starting at $1.66β$1.81/user/month for Adaptive Access module (comprehensive Workforce packages start at ~$3.50β$5.00/user/month; CIAM starts at $0.025/active user/month). | 90-day free trial with full access to SSO, MFA, Adaptive Access, and Identity Analytics across unlimited applications (no credit card required; no perpetual free tier). |
| Cisco Duo | Adaptive authentication and Zero Trust access featuring Risk-Based Factor Selection, Risk-Based Remembered Devices, device health inspection, and phishing-resistant MFA. | ~$200B+ Market Cap (Cisco: ~$54B Rev) |
Duo Essentials starts at $3.00/user/month; Duo Advantage (includes Risk-Based Authentication & Factor Selection) starts at $6.00/user/month; Duo Premier at $9.00/user/month (billed annually). | Free forever for up to 10 users (includes core MFA, Duo Mobile push, passcodes, SSO, and app integrations); 30-day free trial of Duo Advantage for unlimited test users (telephony excluded). |
| Cisco Secure Access | Converged Security Service Edge (SSE) platform integrating continuous identity risk evaluation, ZTNA, device posture validation, Cisco Talos threat intelligence, and adaptive access policies. | ~$200B+ Market Cap (Cisco: ~$54B Rev) |
DNS & Internet security starting tier at $2.25β$4.00/user/month; complete Cisco Secure Access SSE suite starts at ~$7.50β$15.00/user/month (billed annually, min 50 users / ~$4,500/year). | 14-day to 21-day free trial (standard self-service evaluation covering full SSE and zero-trust private access capabilities for up to 50 users; no perpetual free tier). |
| CrowdStrike Falcon Identity Protection | Identity Threat Detection and Response (ITDR) offering real-time hybrid AD and Entra ID attack detection, behavioral baselining, and automated conditional step-up MFA enforcement. | ~$60B+ Market Cap (CrowdStrike: ~$3.5B+ Rev) |
Licensed per active identity starting at ~$3.50β$6.00/identity/month ( |
15-day free trial of the CrowdStrike Falcon platform (includes Next-Gen Identity Security and Falcon Identity Protection module evaluation, no credit card required; no perpetual free tier). |
| Cloudflare Zero Trust | Edge-native Zero Trust network access (ZTNA) and Secure Web Gateway with device posture validation, contextual risk signals, conditional step-up policies, and browser isolation. | ~$30B Market Cap (Cloudflare: ~$1.5B Rev) |
Free tier is $0.00/month; Standard Pay-as-you-go plan starts at $7.00/user/month; Enterprise contracts start at $14.00β$20.00/user/month (billed monthly or annually). | Free forever for up to 50 users (includes full ZTNA, Secure Web Gateway DNS/HTTP filtering, WARP client, 24-hour log retention, and up to 3 physical network locations). |
| Okta Adaptive MFA | Behavioral intelligence and risk engine assessing device trust, network, location velocity, ThreatInsight IP reputation, and dynamic step-up authentication. | ~$15B Market Cap (Okta: ~$2.4B+ Rev) |
Standalone Adaptive MFA is $6.00/user/month (billed annually; subject to Okta's $1,500/year minimum contract spend); included in Workforce Identity Cloud Essentials Suite at $17.00/user/month. | 30-day free trial of Okta Workforce Identity Cloud (full access to Adaptive MFA, SSO, ThreatInsight, and Universal Directory for up to 100 test users; no perpetual free tier). |
| Auth0 Adaptive MFA | Developer-first CIAM and adaptive security featuring Attack Protection, impossible travel anomaly detection, brute-force defense, breached password alerts, and dynamic step-up challenges. | ~$15B Market Cap (Okta acquired Auth0 for $6.5B) |
B2C Essentials starts at $35.00/month (up to 500 MAU; $150.00/month for B2B); Professional starts at $240.00/month; Enterprise tier with Adaptive MFA add-on starts at ~$1,000.00β$2,000.00/month (~$12,000β$24,000/year). | Free forever for up to 25,000 Monthly Active Users (MAUs) (includes unlimited social logins, passwordless login, 1 custom domain, and basic attack protection; Adaptive MFA requires Enterprise); 22-day free trial of Enterprise features. |
| Ping Identity | Adaptive authentication platform evaluating contextual signals (location, device, IP, user behavior) with dynamic policy trees, adaptive MFA step-up, and workforce/CIAM federation. | ~$2.8B Valuation (Thoma Bravo; ~$350M+ ARR) |
PingOne for Workforce Essential starts at $3.00/user/month; PingOne Plus (with adaptive MFA and risk policies) starts at $6.00/user/month (billed annually; enterprise contracts typically require ~$15,000β$50,000/year minimums). | 30-day free trial of PingOne (includes complete access to adaptive MFA, risk management, user directories, and SSO for up to 100 test users; no perpetual free tier). |
| ForgeRock | Dynamic identity orchestration journeys supporting behavioral biometrics, device intelligence, continuous contextual evaluation, and adaptive step-up authentication (PingOne Advanced Identity Cloud). | ~$2.3B Valuation (Merged with Ping Identity) |
Base enterprise cloud tier starts at ~$2.00β$4.00/user/month or ~$8,000/month (~$96,000/year baseline enterprise contract scaled by MAU; CIAM tiers start at ~$0.03/MAU/month). | 30-day guided Proof of Concept (PoC) / sandbox trial with full access to identity orchestration journeys and adaptive authentication nodes (no perpetual free tier). |
| RSA Adaptive Authentication | Machine learning risk engine, behavioral analytics, device fingerprinting, fraud detection, and transaction monitoring for dynamic step-up MFA across hybrid IT (RSA ID Plus). | ~$2.0B+ Valuation (Clearlake / STG; ~$300M+ Rev) |
RSA ID Plus E1 starts at $3.00/user/month; ID Plus E2/E3 (includes advanced risk engine, behavioral analytics, and contextual access) starts at $5.00β$7.00/user/month (billed annually, min 100 users / ~$3,600β$6,000/year base). | 45-day free trial of RSA ID Plus (includes MFA, SSO, risk engine, and passwordless authentication for up to 50 test users; no perpetual free tier). |
| OneLogin | Contextual access management featuring SmartFactor Authentication, Vigilance AI machine learning risk scoring, device trust policies, SSO, and adaptive step-up MFA. | ~$1.5B Parent Valuation (One Identity / Quest; ~$500M Rev) |
Advanced plan starts at $4.00/user/month; Enterprise tier with SmartFactor Authentication and Vigilance AI risk scoring starts at $8.00/user/month (billed annually; minimum contract of ~$1,500/year). | 30-day free trial of OneLogin Enterprise (full access to SmartFactor Authentication, Vigilance AI risk engine, adaptive MFA, and SSO for up to 50 test users; no credit card required; no perpetual free tier). |
| Silverfort | Agentless unified identity protection platform that enforces risk-based authentication and MFA across Active Directory, legacy protocols (Kerberos, NTLM), command-line tools, service accounts, and cloud IAM. | ~$1.0B Valuation (Series D, ~$50M ARR) |
Starts at ~$3.00β$6.00/user/month (~$36.00β$72.00/user/year) with enterprise deployments typically starting at a $20,000/year minimum contract spend (or 250-user minimum). | 14-day to 30-day Proof of Concept (PoC) free trial in an organization's active directory/scoped environment (includes Identity Security Assessment identifying unmanaged service accounts and MFA gaps; no perpetual free tier). |
| SecureAuth | Arculix Risk Engine delivering continuous behavioral authentication, device fingerprinting, invisible MFA, geo-velocity checks, and threat intelligence-driven step-up access. | ~$300M Valuation (ARR: ~$40M+) |
Base MFA starts at $1.50β$2.00/user/month; full Arculix continuous risk engine & adaptive authentication package starts at $3.00β$5.00/user/month (billed annually, annual contract minimum ~$5,000/year). | 14-day free trial of SecureAuth CIAM and Arculix passwordless authentication (full evaluation of adaptive risk engine and step-up flows; no perpetual free tier). |
Important distinction: There is no single universally adopted open-source drop-in replacement for Duo RBA, Silverfort, Okta Adaptive MFA or Microsoft Entra ID Protection.
The open-source ecosystem is instead composed of:
- Identity providers
- MFA engines
- Authentication policy engines
- Risk engines
- Behavioral analytics
- Device intelligence
- Threat-intelligence systems
- SIEM/logging
- Policy-as-code engines
- Machine-learning infrastructure
Combining these components can produce a highly capable self-hosted RBA platform.
Each repository includes a live GitHub star badge that links directly to its stargazers page.
| Repository π¦ | GitHub_Stars π | Focus Area π | Description & Role π |
|---|---|---|---|
| Elasticsearch | Security Analytics & Telemetry | Distributed search and analytics engine for centralizing authentication logs, behavioral analysis, and anomaly detection. | |
| Headscale | Self-Hosted Zero Trust Mesh | Open-source control server for Tailscale WireGuard overlay networks enforcing identity-aware access rules. | |
| Keycloak | Identity & Adaptive Auth Flows | Leading open-source identity and access management platform supporting conditional authentication flows, adaptive MFA, and WebAuthn. | |
| Authelia | Authentication & Access Control | Lightweight authentication and authorization server providing 2FA/MFA, WebAuthn, TOTP, and reverse-proxy policy enforcement. | |
| FingerprintJS | Browser & Device Fingerprinting | Client-side browser and device fingerprinting library providing hardware and environment signals for risk scoring. | |
| authentik | Identity & Expression Policies | Open-source IdP with flexible Python expression policies, MFA enforcement, user flows, and modern directory integrations. | |
| Teleport | Zero Trust Access & Per-Session MFA | Identity-native infrastructure access proxy with device trust inspection, per-session MFA challenges, and continuous audit. | |
| Casbin | Authorization Library | Powerful authorization library supporting access control models including ACL, RBAC, ABAC, and RESTful path-based policies. | |
| Wazuh | SIEM & Threat Detection | Open-source security monitoring and XDR platform correlating endpoint events, authentication logs, and threat indicators. | |
| SuperTokens | Auth & Session Risk Management | Modular open-source authentication solution featuring session theft protection, rolling session tokens, and adaptive MFA. | |
| ZITADEL | Cloud-Native IAM & Passkeys | Cloud-native identity platform with turnkey multi-tenancy, passkey/WebAuthn support, and contextual session validation. | |
| CrowdSec | Crowdsourced Threat Intel & IPS | Open-source collaborative intrusion prevention system and IP reputation network detecting brute-force and malicious login attempts. | |
| Logto | Modern IAM & CIAM | Developer-friendly alternative to Auth0 supporting enterprise SSO, MFA, passwordless login, and webhook security triggers. | |
| Casdoor | UI-First IAM & Federation | UI-centric identity management and SSO platform supporting OAuth2, OIDC, SAML, WebAuthn, and multi-factor step-up authentication. | |
| Ory Kratos | Headless IAM & MFA | Cloud-native identity and user management system supporting multi-factor authentication, passkeys, and risk-aware self-service flows. | |
| OpenSearch | Search & Anomaly Detection | Open-source search and analytics suite offering automated anomaly detection on authentication telemetry and login events. | |
| Open Policy Agent (OPA) | Policy-as-Code Engine | General-purpose policy engine enabling context-aware risk evaluations, attribute-based access decisions, and decoupled auth rules. | |
| OpenCTI | Cyber Threat Intelligence | Open-source platform for structuring, correlating, and consuming threat intelligence feeds and malicious IP reputation. | |
| Falco | Runtime Threat Detection | De facto Kubernetes threat detection engine analyzing system calls and behavioral anomalies in real time. | |
| MISP | Threat Sharing & Indicators | Open-source threat sharing and indicator correlation platform tracking malicious IPs, compromised credentials, and botnets. | |
| OpenFGA | Relationship-Based Authorization | Zanzibar-inspired open-source fine-grained authorization engine designed for complex resource permissions and context checks. | |
| Ory Keto | Access Control & Zanzibar Server | High-performance access control server implementing Google Zanzibar relation-based access control (ReBAC). | |
| Kanidm | Identity Directory & WebAuthn | Modern, fast identity directory and authentication server written in Rust with built-in passkey and WebAuthn support. | |
| HashiCorp Boundary | Identity-Based Privileged Access | Identity-aware access management for secure infrastructure access without exposing underlying private networks. | |
| TheHive | Security Incident Response | Scalable security incident response platform integrated with MISP for investigating compromised user accounts. | |
| Shuffle | Open-Source SOAR & Remediation | Open-source security orchestration and automated response platform for automated risk remediation and account lockouts. | |
| ClientJS | Browser Fingerprinting | Pure JavaScript device and browser fingerprinting library for collecting client-side environment attributes. | |
| privacyIDEA | Enterprise Multi-Factor Auth | Modular authentication and token management system supporting WebAuthn, TOTP, push tokens, and adaptive MFA workflows. | |
| Cedar | Policy-as-Code Language | AWS-originated expressive policy language for fine-grained contextual authorization and dynamic access control. | |
| FreeIPA | Identity & Domain Security | Integrated identity management system providing centralized LDAP, Kerberos, DNS, and host-level certificate policies. | |
| WSO2 Identity Server | Enterprise RBA & Adaptive IAM | Enterprise IAM platform with native adaptive authentication scripts, behavioral risk scoring, and geo-velocity evaluation. | |
| ua-parser | User-Agent Parsing Engine | Regex-based cross-language user-agent parser for extracting OS, browser, and device telemetry from HTTP headers. | |
| Gluu / Janssen | Cloud-Native IAM & FIDO2 | Cloud-native Linux Foundation identity platform with FIDO2/WebAuthn, UMA, and custom scriptable authentication steps. | |
| Apache Syncope | Enterprise Identity Lifecycle | Open-source digital identity management system for managing identity lifecycle, provisioning, and governance. | |
| OpenSearch Security Analytics | Security Correlation Engine | OpenSearch plugin providing Sigma rule-based threat detection and automated security event correlation. | |
| LemonLDAP::NG | Web SSO & Access Control | Modular Web-SSO and identity federation system with fine-grained access rules and session policy enforcement. |
The open-source ecosystem is instead composed of:
- Identity providers
- MFA engines
- Authentication policy engines
- Risk engines
- Behavioral analytics
- Device intelligence
- Threat-intelligence systems
- SIEM/logging
- Policy-as-code engines
- Machine-learning infrastructure
Combining these components can produce a highly capable self-hosted RBA platform.
GitHub: https://github.com/wso2/product-is
Website: https://wso2.com/identity-server/
One of the strongest open-source candidates for building adaptive authentication.
WSO2 Identity Server supports adaptive authentication and can integrate risk engines and external systems. WSO2 documentation describes contextual signals including device fingerprints, history, geolocation, geo-velocity and behavioral analysis.
Capabilities
- Adaptive authentication
- Conditional authentication
- MFA
- SSO
- OAuth2
- OpenID Connect
- SAML
- Identity federation
- Authentication scripts
- Risk-engine integration
- Device context
- Geolocation
- Geo-velocity
- Behavioral analysis
Best open-source candidate for:
Enterprise RBA
+
Identity Server
+
Adaptive MFA
GitHub: https://github.com/keycloak/keycloak
Website: https://www.keycloak.org/
Keycloak is one of the most important open-source IAM platforms for building an RBA system.
It provides:
- Authentication flows
- Conditional authenticators
- MFA
- WebAuthn
- TOTP
- OTP
- SSO
- OAuth2
- OpenID Connect
- SAML
- Identity brokering
- User federation
- Custom authenticators
- Custom extensions
Risk scoring can be implemented using custom authenticators, authentication flows, event listeners and external risk engines.
GitHub: https://github.com/goauthentik/authentik
Website: https://goauthentik.io/
authentik is an open-source identity provider supporting SAML, OAuth2/OIDC, LDAP, RADIUS and policy-based authentication.
Useful for RBA
- Policy engine
- Expression policies
- MFA
- Device/context policies
- SSO
- OAuth2/OIDC
- LDAP
- RADIUS
- Self-hosting
GitHub: https://github.com/privacyidea/privacyidea
Website: https://privacyidea.org/
Open-source authentication and MFA platform.
Capabilities
- OTP
- TOTP
- HOTP
- WebAuthn
- FIDO2
- Push authentication integrations
- Token management
- Authentication policies
- LDAP/AD integration
- RADIUS
- REST API
Excellent building block for an open-source adaptive MFA architecture.
GitHub: https://github.com/JanssenProject/jans
Website: https://www.jans.io/
Open-source identity and authorization platform.
Capabilities
- OAuth2
- OpenID Connect
- FIDO2
- WebAuthn
- UMA
- Authentication
- Authorization
- Identity federation
- Custom authentication flows
GitHub: https://github.com/LemonLDAPNG/lemonldap-ng
Website: https://lemonldap-ng.org/
Open-source Web SSO and access-management platform.
Capabilities
- SSO
- Access control
- Authentication
- LDAP
- SAML
- OpenID Connect
- CAS
- Policy enforcement
- Session management
GitHub: https://github.com/authelia/authelia
Open-source authentication and authorization server.
Capabilities
- 2FA
- WebAuthn
- TOTP
- OIDC
- Access control
- Session management
- Reverse-proxy integration
Best suited to smaller/self-hosted environments.
GitHub: https://github.com/kanidm/kanidm
Modern open-source identity directory and authentication system.
Capabilities
- Passkeys
- WebAuthn
- MFA
- LDAP-compatible directory functions
- OAuth2/OIDC
- Strong authentication
GitHub: https://github.com/zitadel/zitadel
Open-source identity platform supporting:
- OIDC
- OAuth2
- SAML
- MFA
- Passkeys
- Organizations
- Identity federation
- Fine-grained authorization
GitHub: https://github.com/casdoor/casdoor
Open-source identity and access management platform.
Capabilities
- SSO
- OAuth2
- OIDC
- SAML
- MFA
- Social login
- Identity federation
- Application integration
Website: https://syncope.apache.org/
Open-source identity management platform.
Useful for:
- Identity lifecycle
- Provisioning
- Policy
- Federation
- Enterprise IAM
Website: https://www.shibboleth.net/
Open-source federation and authentication ecosystem.
Particularly relevant to:
- SAML
- Federation
- Higher education
- Enterprise identity federation
Website: https://www.freeipa.org/
Open-source identity management platform integrating:
- LDAP
- Kerberos
- Certificates
- Host identity
- Policy
- Authentication
Useful as an enterprise identity foundation.
A major advantage of an open architecture is that the risk engine can be separated from the identity provider.
GitHub: https://github.com/open-policy-agent/opa
Policy engine for:
- Authorization
- Contextual decisions
- Attribute-based access control
- Policy-as-code
GitHub: https://github.com/cedar-policy/cedar
AWS-originated open-source authorization policy language.
Useful for:
- Fine-grained authorization
- Contextual policies
- Attribute-based access
GitHub: https://github.com/casbin/casbin
Authorization library supporting:
- RBAC
- ABAC
- ACL
- Custom models
GitHub: https://github.com/openfga/openfga
Open-source fine-grained authorization system inspired by Zanzibar.
Useful for:
- Relationship-based authorization
- Resource permissions
- Contextual authorization
GitHub: https://github.com/ory/keto
Open-source authorization server for fine-grained access control.
GitHub: https://github.com/ForgeRock/BehavioSec
The repository provides a continuous-authentication implementation based on behavioral signals such as keystrokes, cursor movements, touch/screen pressure and device handling.
It illustrates an important RBA pattern:
Behavioral Signal
β
Behavioral Score
β
Risk Evaluation
β
Step-Up MFA
β
Allow / Block
GitHub: https://github.com/ChiUkwuDi/Continuous-Authentication-System
Experimental/open-source continuous authentication implementation using:
- Facial recognition
- Voice
- Keystroke dynamics
- Mouse behavior
- Behavioral biometrics
Useful primarily as a research/building-block project rather than a mature enterprise IAM platform.
Device intelligence is one of the most important RBA inputs.
Useful open-source components include:
GitHub: https://github.com/fingerprintjs/fingerprintjs
Browser/device fingerprinting.
GitHub: https://github.com/jackspirou/clientjs
Browser fingerprinting library.
GitHub: https://github.com/ua-parser/uap-core
User-agent parsing.
Browser
β
Device Fingerprint
β
Device Reputation
β
Historical Device Profile
β
Risk Engine
RBA becomes substantially stronger when authentication events are correlated with threat intelligence.
GitHub: https://github.com/MISP/MISP
Open-source threat-intelligence platform.
Useful for:
- IP indicators
- Domains
- Malware indicators
- Threat actors
- IOC correlation
GitHub: https://github.com/OpenCTI-Platform/opencti
Open-source cyber threat-intelligence platform.
Website: https://www.abuseipdb.com/
Useful external IP reputation source.
Website: https://www.spamhaus.org/
IP/domain reputation and threat intelligence.
Website: https://www.maxmind.com/
Useful for:
- Geolocation
- ASN
- Network intelligence
GitHub: https://github.com/opensearch-project/OpenSearch
Useful for:
- Authentication-event analytics
- Anomaly detection
- Search
- Security analytics
- Dashboards
GitHub: https://github.com/elastic/elasticsearch
Useful for:
- Authentication telemetry
- Behavioral analytics
- Risk-event search
- Anomaly detection
Website: https://kafka.apache.org/
Event streaming backbone for RBA.
Website: https://redis.io/
Useful for:
- Real-time risk state
- Session risk
- Counters
- Rate limiting
- Temporary reputation data
Website: https://www.postgresql.org/
Useful for:
- User risk profiles
- Device history
- Authentication history
- Policy data
- Risk decisions
Important open-source components:
| Project | Primary Role |
|---|---|
| Open Policy Agent | Policy-as-code |
| Cedar | Authorization policy |
| Casbin | RBAC/ABAC |
| OpenFGA | Fine-grained authorization |
| Ory Keto | Authorization |
| Keycloak | IAM + authentication policy |
| WSO2 IS | IAM + adaptive authentication |
| authentik | IAM + policy |
| privacyIDEA | MFA + token policy |
| LemonLDAP::NG | SSO + access policy |
| Authelia | Authentication + access policy |
An RBA architecture should normally support:
- OAuth 2.0
- OpenID Connect
- SAML 2.0
- WebAuthn
- FIDO2
- RADIUS
- LDAP
- Kerberos
- SCIM
- JWT
- mTLS
Important open-source implementations include:
- Keycloak
- WSO2 Identity Server
- authentik
- Janssen
- ZITADEL
- LemonLDAP::NG
- Authelia
- privacyIDEA
- FreeIPA
- Shibboleth
- Ory
GitHub: https://github.com/wazuh/wazuh
Open-source security monitoring platform.
Useful for:
- Authentication monitoring
- Endpoint telemetry
- Threat detection
- Log analysis
- SIEM/XDR functions
Website: https://securityonionsolutions.com/
Open-source security monitoring platform integrating multiple security tools.
GitHub: https://github.com/opensearch-project/security-analytics
Useful for correlating:
Authentication Events
+
Endpoint Events
+
Network Events
+
Threat Intelligence
β
Risk Engine
| Commercial Platform | Open-Source / Open Stack Equivalent |
|---|---|
| Cisco Duo RBA | Keycloak + privacyIDEA + OPA + device intelligence |
| Silverfort | Keycloak/WSO2 + OPA + Wazuh + AD/LDAP + risk engine |
| Ping Identity | WSO2 IS / Keycloak + OPA + WebAuthn |
| ForgeRock | WSO2 IS / Keycloak + adaptive authentication extensions |
| Okta Adaptive MFA | Keycloak / authentik / WSO2 + privacyIDEA |
| Microsoft Entra ID Protection | Keycloak/WSO2 + OPA + Wazuh + MISP + behavioral analytics |
| IBM Verify | WSO2 IS + Keycloak + OPA + SIEM |
| RSA Adaptive Authentication | WSO2 + risk engine + ML + threat intelligence |
| SecureAuth | WSO2 + Keycloak + device fingerprint + GeoIP + behavioral analytics |
| OneLogin | authentik / Keycloak / ZITADEL + privacyIDEA |
| Adaptive MFA | Keycloak + privacyIDEA |
| Continuous Authentication | Keycloak + behavioral analytics + session-risk engine |
| Risk-Based Access | OPA + Keycloak + telemetry |
| Identity Threat Detection | Wazuh + OpenSearch + MISP |
| Device Risk | FingerprintJS + device database + risk engine |
| IP Risk | MISP + AbuseIPDB + GeoIP + ASN intelligence |
flowchart TD
A[User] --> B[Application]
B --> C[Identity Provider]
C --> D[Authentication Request]
D --> E[Risk Engine]
E --> F[Device Intelligence]
E --> G[IP Reputation]
E --> H[Geo Location]
E --> I[Behavior Analytics]
E --> J[Threat Intelligence]
E --> K[Identity Risk]
E --> L[Session Context]
E --> M[Risk Score]
M --> N{Policy Decision}
N -->|Low Risk| O[Allow]
N -->|Medium Risk| P[Step-Up MFA]
N -->|High Risk| Q[Block]
N -->|Critical| R[Revoke Session]
P --> S[WebAuthn / FIDO2 / TOTP / Push]
S --> T[Authentication Result]
T --> U[Update Risk Profile]
flowchart LR
U[User] --> APP[Application]
APP --> IDP[Keycloak / WSO2 / authentik]
IDP --> RISK[Risk Engine]
RISK --> DEVICE[Device Intelligence]
RISK --> IP[IP Reputation]
RISK --> GEO[GeoIP]
RISK --> BEHAVIOR[Behavior Analytics]
RISK --> TI[Threat Intelligence]
RISK --> SIEM[Wazuh / OpenSearch]
RISK --> POLICY[OPA / Cedar / Casbin]
POLICY --> DECISION[Allow / MFA / Block]
DECISION --> IDP
IDP --> MFA[privacyIDEA / WebAuthn / FIDO2]
MFA --> APP
sequenceDiagram
participant U as User
participant A as Application
participant I as Identity Provider
participant R as Risk Engine
participant M as MFA
participant S as SIEM
U->>A: Login
A->>I: Authentication request
I->>R: Send context
R->>R: Evaluate risk signals
R->>R: Calculate risk score
alt Low Risk
R->>I: Allow
I->>A: Authentication success
else Medium Risk
R->>I: Require MFA
I->>M: Step-up challenge
M->>I: MFA result
I->>A: Authentication success
else High Risk
R->>I: Block
I->>A: Access denied
end
R->>S: Record risk decision
A simple open-source RBA implementation can start with a weighted model.
Risk Score =
Device Risk
+ IP Risk
+ Geo Risk
+ Behavior Risk
+ Credential Risk
+ Threat Intelligence Risk
+ Session Risk
+ Application Risk
Example:
| Signal | Weight |
|---|---|
| New device | +20 |
| Unknown IP | +15 |
| Malicious IP | +50 |
| Impossible travel | +40 |
| Tor exit node | +30 |
| Abnormal login time | +10 |
| Credential leak | +50 |
| Failed authentication burst | +25 |
| Trusted device | -20 |
| Trusted network | -15 |
| Strong WebAuthn authentication | -30 |
Example policy:
0β29 β Allow
30β49 β Additional verification
50β69 β Strong MFA
70β89 β Restricted access
90β100 β Block
This scoring model is illustrative. Production systems should calibrate thresholds using real authentication telemetry, false-positive rates, attack simulations and business risk.
A production implementation should separate:
SIGNALS
β
FEATURE ENGINEERING
β
RISK MODEL
β
POLICY ENGINE
β
AUTHENTICATION DECISION
For example:
Device = New
IP = Residential
Geo = Normal
Time = Normal
Behavior = Normal
Threat Intel = Clean
Credential = Clean
β
Risk Score = 22
β
ALLOW
Whereas:
Device = New
IP = Tor
Geo = Impossible Travel
Behavior = Abnormal
Credential = Leaked
β
Risk Score = 91
β
BLOCK
Traditional authentication:
LOGIN
β
MFA
β
SESSION
Continuous authentication:
LOGIN
β
RISK ASSESSMENT
β
MFA
β
SESSION
β
CONTINUOUS TELEMETRY
β
RISK RE-EVALUATION
β
ALLOW / STEP-UP / REVOKE
A possible open-source architecture:
Keycloak
+
Behavior Analytics
+
Device Fingerprinting
+
Wazuh
+
OpenSearch
+
OPA
+
WebAuthn
RBA fits naturally into Zero Trust.
flowchart TD
A[Identity] --> E[Risk Engine]
B[Device] --> E
C[Network] --> E
D[Behavior] --> E
F[Threat Intelligence] --> E
G[Application] --> E
H[Session] --> E
E --> I[Policy Engine]
I --> J{Decision}
J -->|Allow| K[Access]
J -->|Step-Up| L[MFA]
J -->|Restrict| M[Limited Access]
J -->|Block| N[Deny]
J -->|Revoke| O[Session Revocation]
A strong fully self-hosted architecture can look like:
βββββββββββββββββββββ
β USERS β
βββββββββββ¬ββββββββββ
β
βΌ
βββββββββββββββββββββ
β APPLICATIONS β
βββββββββββ¬ββββββββββ
β
βΌ
βββββββββββββββββββββ
β KEYCLOAK / WSO2 β
βββββββββββ¬ββββββββββ
β
βΌ
βββββββββββββββββββββ
β RISK ENGINE β
βββββββββββ¬ββββββββββ
β
ββββββββββββββββββββββΌβββββββββββββββββββββ
βΌ βΌ βΌ
Device Risk IP Reputation Behavior
β β β
ββββββββββββββββββββββΌβββββββββββββββββββββ
βΌ
βββββββββββββββββββββ
β POLICY ENGINE β
β OPA / Cedar β
βββββββββββ¬ββββββββββ
β
βββββββββββββββββΌββββββββββββββββ
βΌ βΌ βΌ
ALLOW MFA BLOCK
β
βΌ
βββββββββββββββββββββ
β privacyIDEA / β
β WebAuthn / FIDO2 β
βββββββββββββββββββββ
| Capability | Duo | Silverfort | Ping | Okta | Entra ID Protection | SecureAuth | WSO2 | Keycloak | privacyIDEA | authentik |
|---|---|---|---|---|---|---|---|---|---|---|
| RBA | β | β | β | β | β | β | β | β | β | β |
| Adaptive MFA | β | β | β | β | β | β | β | β | β | β |
| Risk Engine | β | β | β | β | β | β | β | β | β | β |
| Device Intelligence | β | β | β | β | β | β | β | β | β | β |
| Behavioral Analytics | β | β | β | β | β | β | β | β | β | β |
| Geo Risk | β | β | β | β | β | β | β | β | β | β |
| IP Reputation | β | β | β | β | β | β | β | β | β | β |
| Continuous Authentication | β | β | β | β | β | β | β | β | β | β |
| WebAuthn | β | β | β | β | β | β | β | β | β | β |
| SSO | β | β | β | β | β | β | β | β | β | β |
| Open Source | β | β | β | β | β | β | β | β | β | β |
| Self-hosted | β | β | β | β | β | β | β | β | β | β |
Legend:
β
= Strong/native capability
β = Possible through configuration/extensions/integration
β = Not the primary capability
WSO2 Identity Server
+
OPA
+
privacyIDEA
+
MISP
+
MaxMind GeoIP
+
OpenSearch
+
Wazuh
+
PostgreSQL
+
Redis
Best for:
- Enterprise IAM
- Adaptive authentication
- Risk-based MFA
- SIEM integration
- Self-hosting
Keycloak
+
Custom Risk Engine
+
OPA
+
privacyIDEA
+
FingerprintJS
+
MISP
+
GeoIP
+
Redis
+
PostgreSQL
+
OpenSearch
Best for:
- Developers
- Custom IAM
- Kubernetes
- Cloud-native applications
- OIDC/OAuth2 environments
authentik
+
WebAuthn
+
OPA
+
Redis
+
GeoIP
+
OpenSearch
Best for:
- SMB
- Homelab
- Internal applications
- Self-hosted infrastructure
Keycloak
+
privacyIDEA
+
WebAuthn
+
FIDO2
+
OPA
Best for:
Adaptive MFA
+
Strong Authentication
+
Policy Enforcement
Keycloak
+
Wazuh
+
OpenSearch
+
MISP
+
OPA
+
Redis
+
privacyIDEA
Authentication events flow into the security analytics layer:
Authentication
β
Risk Events
β
Wazuh
β
OpenSearch
β
Risk Correlation
β
Policy Decision
β
MFA / Allow / Block
With the correct architecture, open-source components can reproduce a substantial portion of commercial RBA functionality.
- Adaptive MFA
- Risk-based MFA
- Contextual authentication
- Device trust
- IP risk
- Geo risk
- Impossible travel
- Authentication history
- Behavioral scoring
- Threat-intelligence correlation
- Risk scoring
- Policy-based access
- Step-up authentication
- WebAuthn
- FIDO2
- TOTP
- Session revocation
- SIEM integration
- Identity federation
- OAuth2
- OIDC
- SAML
- RADIUS
- LDAP
- Custom risk models
- ML-based anomaly detection
The important limitation is that open-source components do not automatically provide the enormous proprietary telemetry networks and detection models behind some commercial platforms.
For example, an open-source Keycloak installation does not automatically provide:
Global threat intelligence
+
Billions of authentication events
+
Proprietary behavioral models
+
Commercial device reputation
+
Commercial fraud intelligence
+
Vendor-specific identity telemetry
Commercial platforms may therefore have an advantage in:
- Global reputation intelligence
- Proprietary behavioral models
- Detection engineering
- Managed threat intelligence
- Vendor-maintained ML models
- Enterprise support
- Integrated device intelligence
- Managed infrastructure
- Large-scale telemetry
The open-source advantage is:
CONTROL
+
CUSTOMIZATION
+
SELF-HOSTING
+
TRANSPARENCY
+
NO VENDOR LOCK-IN
| Area | Commercial | Open Source |
|---|---|---|
| Identity Provider | Excellent | Excellent |
| MFA | Excellent | Excellent |
| WebAuthn | Excellent | Excellent |
| Risk Engine | Excellent | Build/integrate |
| Device Intelligence | Excellent | Build/integrate |
| Global Threat Intel | Excellent | Integrate |
| Behavioral ML | Excellent | Build/integrate |
| SIEM | Integrated | Strong OSS options |
| Policy Engine | Integrated | Excellent |
| Customization | Medium | Excellent |
| Self Hosting | Limited/varies | Excellent |
| Vendor Lock-in | Higher | Lower |
| Initial Complexity | Lower | Higher |
| Engineering Requirement | Lower | Higher |
| Cost at Scale | Subscription | Infrastructure + engineering |
Keycloak
+
privacyIDEA
+
WebAuthn
+
OPA
+
Device Fingerprinting
+
MISP
Silverfort's broader identity-threat model is difficult to reproduce with a single open-source application.
A reasonable architecture is:
Keycloak / WSO2
+
FreeIPA / LDAP / Active Directory
+
Wazuh
+
OpenSearch
+
OPA
+
MISP
+
Risk Engine
This can provide:
Identity Monitoring
+
Risk Detection
+
Adaptive Authentication
+
Policy Enforcement
WSO2 Identity Server
+
Keycloak
+
OPA
+
privacyIDEA
+
WebAuthn
WSO2 Identity Server
+
Keycloak
+
Custom Authentication Flows
+
OPA
+
Behavior Analytics
Keycloak / authentik
+
privacyIDEA
+
WebAuthn
+
OPA
+
Device Intelligence
Keycloak
+
Wazuh
+
OpenSearch
+
MISP
+
OPA
+
Device Intelligence
+
Behavior Analytics
WSO2
+
Device Fingerprinting
+
GeoIP
+
Behavior Analytics
+
OPA
+
WebAuthn
SecureAuth's current architecture explicitly combines device, location/network and behavioral risk analyzers, making this a particularly good model for an open-source RBA design.
flowchart TB
USER[User]
APP[Application]
IDP[Keycloak / WSO2 / authentik]
RISK[Risk Engine]
DEVICE[Device Fingerprinting]
GEO[GeoIP / Geo-velocity]
IPREP[IP Reputation]
BEHAVIOR[Behavior Analytics]
THREAT[MISP / OpenCTI]
IDENTITY[Identity Risk]
SESSION[Session Risk]
POLICY[OPA / Cedar / Casbin]
MFA[WebAuthn / FIDO2 / privacyIDEA]
SIEM[Wazuh / OpenSearch]
DB[(PostgreSQL)]
CACHE[(Redis)]
USER --> APP
APP --> IDP
IDP --> RISK
RISK --> DEVICE
RISK --> GEO
RISK --> IPREP
RISK --> BEHAVIOR
RISK --> THREAT
RISK --> IDENTITY
RISK --> SESSION
RISK --> POLICY
POLICY -->|LOW| ALLOW[ALLOW]
POLICY -->|MEDIUM| MFA
POLICY -->|HIGH| BLOCK[BLOCK]
POLICY -->|CRITICAL| REVOKE[REVOKE SESSION]
MFA --> IDP
RISK --> DB
RISK --> CACHE
IDP --> SIEM
RISK --> SIEM
MFA --> SIEM
A production-grade open-source RBA engine should ideally contain these components:
βββββββββββββββββββββββββββββββββββββββββββββββ
β RISK ENGINE β
βββββββββββββββββββββββββββββββββββββββββββββββ€
β β
β Signal Collector β
β β β
β Feature Extraction β
β β β
β Rule Engine β
β β β
β ML / Anomaly Model β
β β β
β Risk Aggregator β
β β β
β Policy Engine β
β β β
β Decision β
β β
βββββββββββββββββββββββββββββββββββββββββββββββ
POST /risk/evaluate
Content-Type: application/json{
"user": "user123",
"application": "finance",
"ip": "203.0.113.10",
"country": "IN",
"device_id": "device-123",
"device_trusted": false,
"vpn": true,
"tor": false,
"new_device": true,
"impossible_travel": false,
"behavior_anomaly": true,
"credential_compromised": false
}Response:
{
"risk_score": 67,
"risk_level": "HIGH",
"decision": "STEP_UP",
"required_authentication": "WEBAUTHN"
}risk_policy:
low:
score: 0-29
action: allow
medium:
score: 30-49
action: step_up
factor: totp
high:
score: 50-79
action: step_up
factor: webauthn
critical:
score: 80-100
action: blockKafka or another event-streaming system can be used to process authentication events in real time.
flowchart LR
AUTH[Authentication Event]
AUTH --> KAFKA[Kafka]
KAFKA --> STREAM[Stream Processing]
STREAM --> FEATURE[Feature Store]
FEATURE --> MODEL[Risk Model]
MODEL --> POLICY[Policy Engine]
POLICY --> DECISION[Decision]
DECISION --> IDP[Identity Provider]
DECISION --> SIEM[SIEM]
An advanced implementation can use machine learning.
Authentication Events
β
Feature Engineering
β
Historical User Profile
β
Anomaly Detection
β
Risk Probability
β
Policy Engine
β
Adaptive Authentication
Potential open-source ML stack:
Python
+
scikit-learn
+
XGBoost
+
PyTorch
+
ONNX Runtime
+
MLflow
+
Redis
+
PostgreSQL
Useful signals:
- Login frequency
- Login hour
- Device changes
- IP changes
- Geographic distance
- Authentication failures
- MFA failures
- Application accessed
- Resource sensitivity
- Session duration
- Behavioral deviation
User: Alice
Normal:
Country = India
City = Kolkata
Device = Laptop-01
Time = 09:00β18:00
IP = Corporate Network
Current Login:
Country = Germany
Device = Unknown
Time = 03:17
IP = Tor Exit Node
Behavior = Abnormal
Credential = Previously Leaked
β
RISK ENGINE
β
RISK = 94/100
β
BLOCK
User: Bob
Known identity
Known country
New device
Unknown Wi-Fi
Normal behavior
No threat intelligence match
β
RISK = 43
β
STEP-UP MFA
β
WebAuthn
β
ALLOW
User: Carol
Known device
Known network
Normal location
Normal time
Normal behavior
No threat intelligence
Strong authentication
β
RISK = 8
β
ALLOW
The strongest architecture separates three decisions:
WHO ARE YOU?
β
Identity
HOW RISKY IS THIS REQUEST?
β
Risk
WHAT ARE YOU ALLOWED TO DO?
β
Authorization
Therefore:
Authentication β Risk β Authorization
A mature architecture combines all three.
authentik
+
WebAuthn
+
TOTP
+
OPA
Keycloak
+
privacyIDEA
+
OPA
+
Wazuh
+
OpenSearch
WSO2 / Keycloak
+
privacyIDEA
+
OPA
+
MISP
+
OpenCTI
+
Wazuh
+
OpenSearch
+
Kafka
+
Redis
+
PostgreSQL
+
ML Risk Engine
Keycloak / WSO2
+
FIDO2 / WebAuthn
+
privacyIDEA
+
OPA
+
Device Intelligence
+
MISP
+
Behavior Analytics
+
Wazuh
+
OpenSearch
+
ML Risk Engine
+
Continuous Session Evaluation
| Project | Role |
|---|---|
| WSO2 Identity Server | Adaptive authentication / IAM |
| Keycloak | IAM / MFA / authentication flows |
| privacyIDEA | MFA / token management |
| authentik | IAM / SSO / policy |
| OPA | Policy engine |
| MISP | Threat intelligence |
| Wazuh | Security monitoring |
| OpenSearch | Analytics / SIEM |
| WebAuthn/FIDO2 | Phishing-resistant authentication |
| Project | Role |
|---|---|
| Janssen | Open-source IAM |
| ZITADEL | IAM |
| LemonLDAP::NG | SSO / access control |
| Authelia | Authentication |
| Kanidm | Identity / authentication |
| Casdoor | IAM |
| OpenFGA | Fine-grained authorization |
| Cedar | Authorization |
| Casbin | RBAC/ABAC |
| OpenCTI | Threat intelligence |
| Apache Kafka | Event streaming |
| Redis | Real-time state |
| PostgreSQL | Identity/risk data |
| Project / Technology | Role |
|---|---|
| FingerprintJS | Device fingerprinting |
| MaxMind GeoIP | Geolocation |
| AbuseIPDB | IP reputation |
| Spamhaus | Threat reputation |
| OpenCV | Behavioral/computer vision |
| PyTorch | ML |
| scikit-learn | ML |
| XGBoost | Risk modelling |
| MLflow | ML lifecycle |
| ONNX Runtime | Model inference |
| Prometheus | Metrics |
| Grafana | Visualization |
| Loki | Log aggregation |
| Vector | Telemetry pipeline |
| Fluent Bit | Log collection |
| Requirement | Recommended Project |
|---|---|
| Adaptive authentication | WSO2 Identity Server |
| General-purpose IAM | Keycloak |
| Adaptive MFA building block | privacyIDEA |
| Self-hosted SSO | authentik |
| Policy engine | OPA |
| Fine-grained authorization | OpenFGA |
| Threat intelligence | MISP |
| Threat intelligence graph | OpenCTI |
| Security monitoring | Wazuh |
| SIEM/search | OpenSearch |
| Device fingerprinting | FingerprintJS |
| WebAuthn | Keycloak / authentik / privacyIDEA |
| Identity directory | FreeIPA / Kanidm |
| Federation | Shibboleth / Keycloak / WSO2 |
| ML risk engine | Python + scikit-learn/XGBoost/PyTorch |
| Event streaming | Kafka |
| Real-time state | Redis |
If the primary objective is:
"Build an open-source Risk-Based Authentication platform rather than simply installing an open-source IdP."
the most practical architecture is:
βββββββββββββββββββ
β Keycloak β
β or β
β WSO2 β
ββββββββββ¬βββββββββ
β
βΌ
βββββββββββββββββββ
β RISK ENGINE β
ββββββββββ¬βββββββββ
β
ββββββββββββββββββββΌβββββββββββββββββββ
β β β
βΌ βΌ βΌ
Device Risk IP Risk Behavior
β β β
ββββββββββββββββββββΌβββββββββββββββββββ
βΌ
βββββββββββββββββββ
β OPA β
ββββββββββ¬βββββββββ
β
βββββββββββββΌββββββββββββ
βΌ βΌ βΌ
ALLOW MFA BLOCK
β
βΌ
βββββββββββββββββββ
β privacyIDEA / β
β WebAuthn / FIDO β
βββββββββββββββββββ
This is much closer to the architecture of a true RBA platform than simply deploying an MFA server.
A common mistake is:
Keycloak
β
MFA
and calling it "Risk-Based Authentication."
That is adaptive MFA only if the MFA decision actually changes according to risk.
A true RBA architecture should be:
Authentication
β
Context Collection
β
Risk Calculation
β
Policy Evaluation
β
Dynamic Authentication Requirement
β
Authentication
β
Continuous Risk Monitoring
flowchart TD
A[Authentication Request]
A --> B[Collect Signals]
B --> C[Device]
B --> D[IP]
B --> E[Location]
B --> F[Behavior]
B --> G[Threat Intelligence]
B --> H[Identity]
B --> I[Session]
B --> J[Application]
C --> K[Risk Engine]
D --> K
E --> K
F --> K
G --> K
H --> K
I --> K
J --> K
K --> L[Risk Score]
L --> M{Policy}
M -->|0-29| N[Allow]
M -->|30-49| O[Basic Step-Up]
M -->|50-79| P[Strong MFA]
M -->|80-89| Q[Restricted Access]
M -->|90-100| R[Block / Revoke]
A production RBA system should protect against:
- MFA fatigue
- MFA push bombing
- Credential stuffing
- Password spraying
- Session hijacking
- Token theft
- Cookie theft
- Device spoofing
- Fingerprint spoofing
- IP reputation manipulation
- VPN/Tor evasion
- GeoIP inaccuracies
- False positives
- Model poisoning
- Behavioral-model poisoning
- Risk-engine bypass
- Policy misconfiguration
- Break-glass account lockout
Important controls:
FIDO2 / WebAuthn
+
Phishing-resistant MFA
+
Short-lived sessions
+
Token binding where applicable
+
Continuous risk evaluation
+
Strong logging
+
Policy versioning
+
Audit trails
+
Rate limiting
+
Break-glass accounts
Risk-based authentication can process highly sensitive contextual information.
Potentially sensitive data includes:
- Location
- IP address
- Device fingerprint
- Behavioral patterns
- Login history
- Biometric/behavioral characteristics
- Network information
Therefore:
Collect minimum necessary data
+
Encrypt data
+
Limit retention
+
Apply access controls
+
Audit risk-model usage
+
Avoid unnecessary behavioral surveillance
Always verify the current license before deploying an open-source component commercially.
Particularly distinguish between:
Open Source
Source Available
Open Core
Dual Licensed
Commercial Edition
Managed SaaS
Examples:
- Keycloak β open source
- WSO2 Identity Server β open-source project with commercial offerings
- privacyIDEA β open source
- authentik β open-source project with commercial/enterprise offerings
- OPA β open source
- MISP β open source
- Wazuh β open source
- OpenSearch β open-source project
- Some device-intelligence and threat-intelligence services β proprietary APIs
Do not assume that an open-source component automatically provides all commercial enterprise functionality.
LEVEL 1
Static MFA
β
LEVEL 2
Contextual MFA
β
LEVEL 3
Risk-Based MFA
β
LEVEL 4
Behavioral Risk
β
LEVEL 5
Continuous Authentication
β
LEVEL 6
Identity Threat Detection
β
LEVEL 7
Continuous Adaptive Access
A sophisticated open-source implementation should target:
LEVEL 5β7
rather than merely adding TOTP to an identity provider.
For a new project, a strong starting point is:
ββββββββββββββββββββββββββββββββββββββ
β APPLICATIONS β
ββββββββββββββββββ¬ββββββββββββββββββββ
β
βΌ
ββββββββββββββββββββββββββββββββββββββ
β KEYCLOAK β
β Identity / MFA β
ββββββββββββββββββ¬ββββββββββββββββββββ
β
βΌ
ββββββββββββββββββββββββββββββββββββββ
β RISK ENGINE β
β Python / Go / Java β
ββββββββββββββββββ¬ββββββββββββββββββββ
β
βββββββββββΌβββββββββββ
βΌ βΌ βΌ
Device IP/Geo Behavior
β β β
βββββββββββΌβββββββββββ
βΌ
ββββββββββββββββββββββββββββββββββββββ
β OPA β
β Policy Engine β
ββββββββββββββββββ¬ββββββββββββββββββββ
β
βββββββββββΌββββββββββ
βΌ βΌ βΌ
ALLOW MFA BLOCK
β
βΌ
ββββββββββββββββββββββββββββββββββββββ
β privacyIDEA / β
β WebAuthn / FIDO2 β
ββββββββββββββββββββββββββββββββββββββ
WSO2 Identity Server
Best fit when the requirement is specifically:
Identity
+
Adaptive Authentication
+
Risk Signals
+
Authentication Policies
Keycloak
Best when the organization wants maximum customization and a huge developer ecosystem.
privacyIDEA
Best when token/MFA infrastructure is the primary requirement.
authentik
Best for simpler deployments and infrastructure teams.
Open Policy Agent
Best for separating risk decisions from identity infrastructure.
MISP
Best for integrating threat indicators into the risk calculation.
Wazuh + OpenSearch
Best for collecting and correlating authentication/security telemetry.
USER
β
βΌ
βββββββββββββββ
β KEYCLOAK β
β / WSO2 β
ββββββββ¬βββββββ
β
βΌ
βββββββββββββββ
β RISK ENGINE β
ββββββββ¬βββββββ
β
βββββββββββββββββΌβββββββββββββββββ
β β β
βΌ βΌ βΌ
DEVICE IP / GEO BEHAVIOR
RISK RISK RISK
β β β
βββββββββββββββββΌβββββββββββββββββ
β
βΌ
βββββββββββββββ
β OPA β
ββββββββ¬βββββββ
β
ββββββββββββΌβββββββββββ
βΌ βΌ βΌ
ALLOW MFA BLOCK
β
βΌ
βββββββββββββββ
β privacyIDEA β
β WebAuthn β
β FIDO2 β
βββββββββββββββ
This architecture provides the strongest path toward an open-source, self-hosted Risk-Based Authentication platform while retaining the ability to add proprietary or commercial intelligence sources later.
Risk-Based Authentication is not simply another MFA product.
A mature RBA platform combines:
Identity
+
Authentication
+
Device Intelligence
+
Network Intelligence
+
Geolocation
+
Behavior Analytics
+
Threat Intelligence
+
Risk Scoring
+
Policy Engine
+
Adaptive MFA
+
Continuous Session Evaluation
The commercial leaders β Cisco Duo, Silverfort, Ping Identity, ForgeRock, Okta, Microsoft Entra ID Protection, IBM Verify, RSA, SecureAuth and OneLogin β package many of these capabilities into integrated products.
The open-source ecosystem takes a different approach.
The strongest strategy is to assemble:
WSO2 / Keycloak
+
privacyIDEA
+
OPA
+
MISP / OpenCTI
+
Wazuh / OpenSearch
+
Device Intelligence
+
GeoIP / IP Reputation
+
Behavior Analytics
+
Redis / PostgreSQL / Kafka
+
ML Risk Engine
The result can become a highly customizable:
Open-Source Risk-Based Authentication + Adaptive MFA + Continuous Authentication + Identity Risk Platform
with substantially less vendor lock-in and considerably more control over the risk model, authentication policies and security telemetry.
Contributions are welcome.
Please submit:
- New RBA platforms
- Open-source IAM projects
- Adaptive-authentication implementations
- Risk engines
- Device-intelligence projects
- Behavioral-authentication projects
- Threat-intelligence integrations
- Policy engines
- Security analytics tools
- Architecture improvements
- Licensing corrections
This README is intended as a technical reference and architectural comparison.
Capabilities, licensing models, product names, commercial editions and feature availability change over time. Always verify the current documentation and license of each project before production deployment.
RBA thresholds and risk models shown in this document are illustrative and should not be treated as universal security recommendations.
For maximum open-source flexibility:
Keycloak
+
OPA
+
privacyIDEA
+
MISP
+
Wazuh
+
OpenSearch
+
Redis
+
PostgreSQL
+
WebAuthn / FIDO2
+
Custom Risk Engine
This is the closest practical open-source architecture to building a self-hosted alternative to modern commercial Risk-Based Authentication platforms.