TARU PUBLICATIONS
Journal of Information and Optimization Sciences cover
Open Access ·Peer-reviewed·ISSN (Online): 2169-0103·ISSN (Print): 0252-2667
Powered by:DOICrossrefiThenticate

The Journal of Information and Optimization Sciences (JIOS) is a world leading journal publishing high quality, rigorously peer-reviewed original research in all mathematically-oriented theoretical and applied topics in information sciences, optimization sciences and related areas since 1980. Subjects include but are not limited to: • Information Sciences • Optimization Sciences • Control Theory • Operational Research • Decision Sciences • Information Theory • Information Technology • Computer Networks and Communications • Mathematical Programming • Modelling and Simulation • Database Management • Applications to Engineering Sciences • Applications to Technology

Issues up to 2022 co-published with and available at:Taylor & Francis
submissions@tarupublications.com
Open Access Research Article

CyberShield : AI powered broken access control detection and mitigation

* , , , , , ,

* Corresponding author · click or hover a name for details

pp. 1907–1917Vol. 47Issue 5-BMay 2026DOI: 10.47974/JIOS-2283XML
Received:
01 Apr 2025
Published Online:
01 May 2026
Article type:
Research Article
Language:
EN
Article no.:
JIOS-2283
Pages:
1907–1917

Abstract

Broken Access Control (BAC) is identified as the most dangerous and common vulnerability in the modern web systems. BAC can cause severe problems, such as data leaks, privilege escalations and unauthorized system manipulations. To address this issue, we propose to manually construct an extensive and well-featured dataset that can represent realistic traffic-based access control behaviors and behaviors of BAC attacks. This dataset serves as a preliminary resource for developing and evaluating machine learning algorithms capable of real-time BAC attack detection. The study has employed this dataset to develop various machine learning techniques such as Logistic Regression, Random Forest, Gradient Boosting, and XGBoost. Double is the contribution of the proposed work, namely the new BAC dataset that serves as a fundamental requirement for research communities, and a machine learning-based detection framework that is dedicated for real-time attacks detection. The Random Forest classifier achieved the highest overall accuracy (90.5%) and F1-score (0.8627), while XGBoost had the greatest AUC value of 0.9556. The system can also evolve and extended in future using the adaptive learning mechanisms, by adding more variants of attack to Produce a comprehensive set of attacks for a large dataset creation, implementing the detection framework to live environment for proactive prevention and automatic response in real time incidents.

Keywords

Subject Classifications

Primary 94A60Secondary 68T05

References

[1] OWASP Foundation, “OWASP Top 10: Broken Access Control,” (2021). [2] H. Haitao, X. Ke, Y. Shuailin, Z. Bing, Z. Yuxuan, and L. Jiazheng, “Game-based detection method of broken access control vulnerabilities in web applications,” Journal of Communications, vol. 45, no. 6 (2024). [3] A. Anas, S. Elgamal, and B. Youssef, “Survey on detecting and preventing web application broken access control attacks,” International Journal of Electrical and Computer Engineering (IJECE), vol. 14, no. 1, pp. 772–781 (2024). [4] M. N. Nobi, M. Gupta, L. Praharaj, M. Abdelsalam, R. Krishnan, and R. Sandhu, “Machine learning in access control: A taxonomy and survey,” arXiv preprint, arXiv:2207.01739 (2022). [5] M. N. Nobi, R. Krishnan, Y. Huang, M. Shakarami, and R. Sandhu, “Toward deep learning based access control,” in Proc. 12th ACM Conf. Data and Application Security and Privacy, pp. 143–154 (Apr. 2022). [6] N. Shanthi and J. Shreyas, “Research on dataset creation methods for security learning,” SN Computer Science (2022). [7] L. Zhong, “A survey of prevent and detect access control vulnerabilities,” arXiv preprint, arXiv:2103.04553 (2021). [8] H. Es-Samaali, A. Abou El Kalam, A. Outchakoucht, and S. Benhadou, “Machine learning enhanced access control for big data,” arXiv preprint, arXiv:2109.03200 (2021). [9] A. K. Sharma and R. Singh, “Secure flow authentication and CNN-based intrusion detection system,” Journal of Discrete Mathematical Sciences and Cryptography, vol. 27, no. 2, pp. 2628–2645 (2024). [10] S. Verma, P. Gupta, and M. K. Sharma, “Machine learning-based intrusion detection framework for network security,” Journal of Discrete Mathematical Sciences and Cryptography, vol. 26, no. 5, pp. 1987–2003 (2023).[11] R. K. Jain and S. Bansal, “An efficient cryptographic approach for secure data transmission in web applications,” Journal of Discrete Mathematical Sciences and Cryptography, vol. 25, no. 4, pp. 1453–1468 (2022). [12] N. Agarwal and V. Saxena, “Analysis of access control mechanisms in distributed systems,” Journal of Interdisciplinary Mathematics, vol. 24, no. 6, pp. 1567–1582 (2021). [13] P. K. Mishra and A. Tiwari, “A hybrid machine learning approach for anomaly detection in cybersecurity,” Journal of Discrete Mathematical Sciences and Cryptography, vol. 26, no. 3, pp. 1121–1138 (2023). 
Views: 87Downloads: 6Citations: 0