arXiv:cs.LG· Yassin Elsharkawy·· 4 小时前AI 评分33
评估行为上下文对云环境中可解释 IAM 策略风险评分的作用
Evaluating Behavioral Context for Interpretable IAM Policy Risk Scoring in Cloud Environments
AI 导读
一项研究用 AWS IAM Context Bench 的 534 条真实 AWS 观测数据,评估行为与环境上下文能否提升可解释的 IAM 策略风险优先级排序。在统一的分组交叉验证下,纳入 CloudTrail 遥测的全上下文模型显著降低分析师优先级预测误差,并在同策略对照中准确区分良性与会话可疑行为。
正文
Abstract:IAM policy analysis typically emphasizes the authorization capabilities encoded in a policy, but security analyst review priority may also depend on the behavioral and environmental context surrounding a policy event. This paper evaluates whether contextual information provides measurable incremental value for interpretable IAM policy risk prioritization beyond policy and effective-authorization information. AWS is used as the experimental cloud provider because its IAM and audit-telemetry ecosystem enables controlled evaluation using AWS IAM Context Bench, a benchmark containing 534 real AWS experimental observations across policy, environment, and behavioral scenarios, including matched cases where policy and environment remain fixed while behavioral context changes. Three Explainable Boosting Machine models are evaluated under the same leakage-controlled grouped cross-validation protocol: a policy-centric baseline, a policy-plus-environment model, and a full-context model incorporating CloudTrail telemetry. The full-context model substantially reduces analyst-priority prediction error relative to the policy-centric baseline and closely tracks the reference priority ordering. In matched same-policy context pairs, the policy-centric model remains invariant, whereas the full-context model separates benign and suspicious behavioral conditions with high directional accuracy. The results also show improved concentration of high-priority cases at the top of simulated analyst review queues. These findings indicate that behavioral and environmental context can provide useful incremental information for analyst-oriented IAM risk prioritization while preserving an interpretable additive model structure. The formulation is applicable beyond AWS conceptually, although cross-provider validation remains future work.
| Comments: | 6 pages, 5 figures, 5 tables. Peer-reviewed and accepted at IEEE Conference ID# 71863; to appear in the IEEE Xplore proceedings |
| Subjects: | Cryptography and Security (cs.CR); Distributed, Parallel, and Cluster Computing (cs.DC); Machine Learning (cs.LG); Networking and Internet Architecture (cs.NI) |
| Cite as: | arXiv:2610.07345 [cs.CR] |
| (or arXiv:2610.07345v1 [cs.CR] for this version) | |
| https://doi.org/10.48550/arXiv.2610.07345 arXiv-issued DOI via DataCite (pending registration) |
Submission history
From: Yassin Elsharkawy [view email]
[v1]
Mon, 5 Oct 2026 20:17:19 UTC (757 KB)
来源:arXiv:cs.LG · arxiv.org