Javascript must be enabled to continue!
Modeling Privilege Access using NGAC for Cloud Attack Landscape
View through CrossRef
Abstract
The adoption of public clouds, private clouds, and on-premise environments has grown significantly. This business-critical transformation and migration to the cloud have greatly amplified the risks associated with privileged access mismanagement. Traditional Privileged Access Management (PAM) and Identity and Access Management (IAM) solutions struggle to adequately address sophisticated threats, such as privilege escalations, lateral movements, and misconfigurations. To bridge these critical gaps, we propose an innovative PAM framework using the NIST’s Next Generation Access Control (NGAC) applying Hypergraph semantics. We develop model NGAC policy graph as labeled hypergraphs and hy-peredges and apply set-theoretic semantics to evaluate policies as part of the enforcement engine. We establish multi-source, multi-destination policy graphs based on dynamic graph traversals and constraint validations. This unique approach captures dynamic, multi-dimensional privilege relationships , enabling fine-grained, context-aware policy enforcement across diverse cloud infrastructures. Our comprehensive experimental evaluation demonstrates that NGAC combined with hypergraph representations significantly outperforms conventional Attribute-Based Access Control (ABAC) and traditional NGAC graph models, reducing the complexity of privilege mismanagement use-cases from superlinear O(n k) in traditional methods to logarithmic O(n log(n)) in our case, thus markedly improving scalability. Real-world cloud infrastructure use cases validate our method’s ability to swiftly identify over-privileged users, unauthorized privilege escalations, and potential lateral movement attack pathways. This work introduces a novel theoretical framework for dynamic privilege management, fundamentally altering the landscape of access control in distributed cloud systems. By delivering a robust and scalable solution for privilege management in multi-cloud environments , our research provides a critical advancement in cybersecurity practice, offering actionable insights for mitigating high-risk cloud vulner-abilities in near real-time.
Title: Modeling Privilege Access using NGAC for Cloud Attack Landscape
Description:
Abstract
The adoption of public clouds, private clouds, and on-premise environments has grown significantly.
This business-critical transformation and migration to the cloud have greatly amplified the risks associated with privileged access mismanagement.
Traditional Privileged Access Management (PAM) and Identity and Access Management (IAM) solutions struggle to adequately address sophisticated threats, such as privilege escalations, lateral movements, and misconfigurations.
To bridge these critical gaps, we propose an innovative PAM framework using the NIST’s Next Generation Access Control (NGAC) applying Hypergraph semantics.
We develop model NGAC policy graph as labeled hypergraphs and hy-peredges and apply set-theoretic semantics to evaluate policies as part of the enforcement engine.
We establish multi-source, multi-destination policy graphs based on dynamic graph traversals and constraint validations.
This unique approach captures dynamic, multi-dimensional privilege relationships , enabling fine-grained, context-aware policy enforcement across diverse cloud infrastructures.
Our comprehensive experimental evaluation demonstrates that NGAC combined with hypergraph representations significantly outperforms conventional Attribute-Based Access Control (ABAC) and traditional NGAC graph models, reducing the complexity of privilege mismanagement use-cases from superlinear O(n k) in traditional methods to logarithmic O(n log(n)) in our case, thus markedly improving scalability.
Real-world cloud infrastructure use cases validate our method’s ability to swiftly identify over-privileged users, unauthorized privilege escalations, and potential lateral movement attack pathways.
This work introduces a novel theoretical framework for dynamic privilege management, fundamentally altering the landscape of access control in distributed cloud systems.
By delivering a robust and scalable solution for privilege management in multi-cloud environments , our research provides a critical advancement in cybersecurity practice, offering actionable insights for mitigating high-risk cloud vulner-abilities in near real-time.
Related Results
CLOUD COMPUTING - NAVIGATING THE DIGITAL SKY
CLOUD COMPUTING - NAVIGATING THE DIGITAL SKY
“Cloud Computing – Navigating the Digital Sky” is an extensive guide designed to provide a thorough understanding of cloud computing, an essential technology in today’s digital age...
Hybrid Cloud Scheduling Method for Cloud Bursting
Hybrid Cloud Scheduling Method for Cloud Bursting
In the paper, we consider the hybrid cloud model used for cloud bursting, when the computational capacity of the private cloud provider is insufficient to deal with the peak number...
THE ROLE OF CLOUD COMPUTING IN SCALING E-COMMERCE BUSINESSES
THE ROLE OF CLOUD COMPUTING IN SCALING E-COMMERCE BUSINESSES
In the rapidly evolving digital landscape, e-commerce has emerged as a cornerstone of global trade, necessitating robust, scalable solutions to accommodate increasing consumer dema...
Local Similarity-Driven Refinement for Model-Agnostic Ground-Based Cloud Detection
Local Similarity-Driven Refinement for Model-Agnostic Ground-Based Cloud Detection
Cloud cover estimation is of crucial significance in meteorological observations and short-term/long-term weather forecasting, as it directly affects the accuracy of radiation bala...
ThreatBased Security Risk Evaluation in the Cloud
ThreatBased Security Risk Evaluation in the Cloud
Research ProblemCyber attacks are targeting the cloud computing systems, where enterprises, governments, and individuals are outsourcing their storage and computational resources f...
Leveraging Artificial Intelligence for smart cloud migration, reducing cost and enhancing efficiency
Leveraging Artificial Intelligence for smart cloud migration, reducing cost and enhancing efficiency
Cloud computing has become a critical component of modern IT infrastructure, offering businesses scalability, flexibility, and cost efficiency. Unoptimized cloud migration strategi...
AI-driven zero-touch orchestration of edge-cloud services
AI-driven zero-touch orchestration of edge-cloud services
(English) 6G networks demand orchestration systems capable of managing thousands of distributed microservices under sub-millisecond latency constraints. Traditional centralized app...
Aerosol-cloud interaction inferred from MODIS satellite data and global aerosol models
Aerosol-cloud interaction inferred from MODIS satellite data and global aerosol models
Abstract. We have used the Modis satellite data and two global aerosol models to investigate relationships between aerosol optical depth (AOD) and cloud parameters that may be affe...

