arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

评估云环境中可解释IAM策略风险评分的行为上下文

Evaluating Behavioral Context for Interpretable IAM Policy Risk Scoring in Cloud Environments

Yassin Elsharkawy

arXiv 2610.07345首次发表:更新:

发表机构

Capital University(首都大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文评估行为与环境上下文对IAM策略风险评分的增量价值,使用AWS基准和可解释提升机模型,证明完整上下文模型显著提升分析师优先级预测准确性。

AI 中文摘要

IAM策略分析通常强调策略中编码的授权能力,但安全分析师的审查优先级也可能取决于策略事件周围的行为和环境上下文。本文评估了上下文信息是否在策略和有效授权信息之外,为可解释的IAM策略风险优先级排序提供可测量的增量价值。AWS被用作实验云提供商,因为其IAM和审计遥测生态系统支持使用AWS IAM Context Bench进行受控评估,该基准包含534个真实的AWS实验观察,涵盖策略、环境和行为场景,包括策略和环境保持不变而行为上下文变化的匹配案例。在相同的泄漏控制分组交叉验证协议下,评估了三种可解释提升机模型:以策略为中心的基线模型、策略加环境模型,以及包含CloudTrail遥测的完整上下文模型。完整上下文模型相对于以策略为中心的基线模型,大幅降低了分析师优先级预测误差,并紧密跟踪参考优先级排序。在匹配的相同策略上下文对中,以策略为中心的模型保持不变,而完整上下文模型以高方向准确性区分良性行为和可疑行为条件。结果还显示,在模拟分析师审查队列的顶部,高优先级案例的集中度有所提高。这些发现表明,行为和环境上下文可以为面向分析师的IAM风险优先级排序提供有用的增量信息,同时保持可解释的加性模型结构。该公式在概念上适用于AWS之外,但跨提供商验证仍是未来工作。

英文摘要

IAM policy analysis typically emphasizes the authorization capabilities encoded in a policy, but security analyst review priority may also depend on the behavioral and environmental context surrounding a policy event. This paper evaluates whether contextual information provides measurable incremental value for interpretable IAM policy risk prioritization beyond policy and effective-authorization information. AWS is used as the experimental cloud provider because its IAM and audit-telemetry ecosystem enables controlled evaluation using AWS IAM Context Bench, a benchmark containing 534 real AWS experimental observations across policy, environment, and behavioral scenarios, including matched cases where policy and environment remain fixed while behavioral context changes. Three Explainable Boosting Machine models are evaluated under the same leakage-controlled grouped cross-validation protocol: a policy-centric baseline, a policy-plus-environment model, and a full-context model incorporating CloudTrail telemetry. The full-context model substantially reduces analyst-priority prediction error relative to the policy-centric baseline and closely tracks the reference priority ordering. In matched same-policy context pairs, the policy-centric model remains invariant, whereas the full-context model separates benign and suspicious behavioral conditions with high directional accuracy. The results also show improved concentration of high-priority cases at the top of simulated analyst review queues. These findings indicate that behavioral and environmental context can provide useful incremental information for analyst-oriented IAM risk prioritization while preserving an interpretable additive model structure. The formulation is applicable beyond AWS conceptually, although cross-provider validation remains future work.

Comments6 pages, 5 figures, 5 tables. Peer-reviewed and accepted at IEEE Conference ID# 71863; to appear in the IEEE Xplore proceedings

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑