Open Access
·Peer-reviewed·ISSN (Online): 2169-0103·ISSN (Print): 0252-2667
Powered by:DOICrossrefiThenticate
The Journal of Information and Optimization Sciences (JIOS) is a world leading journal publishing high quality, rigorously peer-reviewed original research in all mathematically-oriented theoretical and applied topics in information sciences, optimization sciences and related areas since 1980. Subjects include but are not limited to:
• Information Sciences
• Optimization Sciences
• Control Theory
• Operational Research
• Decision Sciences
• Information Theory
• Information Technology
• Computer Networks and Communications
• Mathematical Programming
• Modelling and Simulation
• Database Management
• Applications to Engineering Sciences
• Applications to Technology
Issues up to 2022 co-published with and available at:
CyberShield : AI powered broken access control detection and mitigation
*Aashmit MckenzieCorresponding authoraashmit.mckenzie.btech2022@sitpune.edu.inDepartment of Computer Science and Engineering Symbiosis Institute of Technology (SIT) Symbiosis International (Deemed University) Lavale Pune, Maharashtra, 412115, IndiaView full profile →
, Malay Doshimalay.doshi.btech2022@sitpune.edu.inDepartment of Computer Science and Engineering Symbiosis Institute of Technology (SIT) Symbiosis International (Deemed University) Lavale Pune, Maharashtra, 412115, IndiaView full profile →
, Gauri Deogharegauri.deoghare.btech2022@sitpune.edu.inDepartment of Computer Science and Engineering Symbiosis Institute of Technology (SIT) Symbiosis International (Deemed University) Lavale Pune, Maharashtra, 412115, IndiaView full profile →
, Ranjeet Bidweranjeet.bidwe@sitpune.edu.inDepartment of Computer Science and Engineering Symbiosis Institute of Technology (SIT) Symbiosis International (Deemed University) LavaleDepartment of Computer Science and Engineering Symbiosis Institute of Technology (SIT) Symbiosis International (Deemed University) LavalePune, Maharashtra, 412115, IndiaView full profile →
, Sonali Kotharisonali.kothari@sitpune.edu.inDepartment of Computer Science and Engineering Symbiosis Institute of Technology (SIT) Symbiosis International (Deemed University) Lavale Department of Computer Science and Engineering Symbiosis Institute of Technology Symbiosis International (Deemed University) LavalePune, Maharashtra, 412115, IndiaView full profile →
, Pooja Baganepooja.bagane@sitpune.edu.inDepartment of Computer Science and Engineering Symbiosis Institute of Technology (SIT) Symbiosis International (Deemed University) Lavale Department of Computer Science and Engineering Symbiosis Institute of Technology Symbiosis International (Deemed University) LavalePune, Maharashtra, 412115, IndiaView full profile →
, Ankur Goyalankur_gg5781@yahoo.co.inDepartment of Computer Science and Engineering Symbiosis Institute of Technology (SIT) Symbiosis International (Deemed University) LavaleDepartment of Computer Science and Engineering Symbiosis Institute of Technology Symbiosis International (Deemed University) LavalePune, Maharashtra, 412115, IndiaView full profile →
* Corresponding author · click or hover a name for details
Broken Access Control (BAC) is identified as the most dangerous and common vulnerability in the modern web systems. BAC can cause severe problems, such as data leaks, privilege escalations and unauthorized system manipulations. To address this issue, we propose to manually construct an extensive and well-featured dataset that can represent realistic traffic-based access control behaviors and behaviors of BAC attacks. This dataset serves as a preliminary resource for developing and evaluating machine learning algorithms capable of real-time BAC attack detection. The study has employed this dataset to develop various machine learning techniques such as Logistic Regression, Random Forest, Gradient Boosting, and XGBoost. Double is the contribution of the proposed work, namely the new BAC dataset that serves as a fundamental requirement for research communities, and a machine learning-based detection framework that is dedicated for real-time attacks detection. The Random Forest classifier achieved the highest overall accuracy (90.5%) and F1-score (0.8627), while XGBoost had the greatest AUC value of 0.9556. The system can also evolve and extended in future using the adaptive learning mechanisms, by adding more variants of attack to Produce a comprehensive set of attacks for a large dataset creation, implementing the detection framework to live environment for proactive prevention and automatic response in real time incidents.
[1] OWASP Foundation, “OWASP Top 10: Broken Access Control,” (2021). [2] H. Haitao, X. Ke, Y. Shuailin, Z. Bing, Z. Yuxuan, and L. Jiazheng, “Game-based detection method of broken access control vulnerabilities in web applications,” Journal of Communications, vol. 45, no. 6 (2024). [3] A. Anas, S. Elgamal, and B. Youssef, “Survey on detecting and preventing web application broken access control attacks,” International Journal of Electrical and Computer Engineering (IJECE), vol. 14, no. 1, pp. 772–781 (2024). [4] M. N. Nobi, M. Gupta, L. Praharaj, M. Abdelsalam, R. Krishnan, and R. Sandhu, “Machine learning in access control: A taxonomy and survey,” arXiv preprint, arXiv:2207.01739 (2022). [5] M. N. Nobi, R. Krishnan, Y. Huang, M. Shakarami, and R. Sandhu, “Toward deep learning based access control,” in Proc. 12th ACM Conf. Data and Application Security and Privacy, pp. 143–154 (Apr. 2022). [6] N. Shanthi and J. Shreyas, “Research on dataset creation methods for security learning,” SN Computer Science (2022). [7] L. Zhong, “A survey of prevent and detect access control vulnerabilities,” arXiv preprint, arXiv:2103.04553 (2021). [8] H. Es-Samaali, A. Abou El Kalam, A. Outchakoucht, and S. Benhadou, “Machine learning enhanced access control for big data,” arXiv preprint, arXiv:2109.03200 (2021). [9] A. K. Sharma and R. Singh, “Secure flow authentication and CNN-based intrusion detection system,” Journal of Discrete Mathematical Sciences and Cryptography, vol. 27, no. 2, pp. 2628–2645 (2024). [10] S. Verma, P. Gupta, and M. K. Sharma, “Machine learning-based intrusion detection framework for network security,” Journal of Discrete Mathematical Sciences and Cryptography, vol. 26, no. 5, pp. 1987–2003 (2023).[11] R. K. Jain and S. Bansal, “An efficient cryptographic approach for secure data transmission in web applications,” Journal of Discrete Mathematical Sciences and Cryptography, vol. 25, no. 4, pp. 1453–1468 (2022). [12] N. Agarwal and V. Saxena, “Analysis of access control mechanisms in distributed systems,” Journal of Interdisciplinary Mathematics, vol. 24, no. 6, pp. 1567–1582 (2021). [13] P. K. Mishra and A. Tiwari, “A hybrid machine learning approach for anomaly detection in cybersecurity,” Journal of Discrete Mathematical Sciences and Cryptography, vol. 26, no. 3, pp. 1121–1138 (2023).
Views: 87Downloads: 6Citations: 0
Install Journal of Information and Optimization SciencesFaster access from your home screen