Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Optimizing Access Control Policies Using Game Theory: A Nash Equilibrium Approach
University West, Department of Engineering Science.
University West, Department of Engineering Science.
2025 (English)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE creditsStudent thesis
Abstract [sv]

Den här artikeln diskuterar en ny metod för optimal utformning av åtkomst policyer med hjälp av spelteorins principer för att balansera dynamiken mellan rollbaserad åtkomstkon-troll (RBAC) och attributbaserad åtkomstkontroll (ABAC). Den modellerar policydesign processen som den strategiska interaktionen mellan angripare och försvarare med hjälp av Nash Equilibrium analys för att fastställa en optimal policyablandning som förbättrar säker-heten.

Projektet är baserat på empirisk statistik från IBM Cost of a Data Breach Report 2024 som ger detaljerad statistik över kostnaden. Det är också baserat på framgångsfrekvenser för vanliga cyberattacker som Phishing och Token Theft. Dessa framgångsfrekvenser härleddes från två simuleringsmiljöer. Denna statistik används för att uppskatta realistiska utbetalningsmatriser, som sedan används för att beräkna Nash Equilibrium.

Resultaten stöds sedan med hjälp av agentbaserade simuleringar baserade på Mesa-ramverket, där prestanda för policyinställningar kan observeras under dynamiska scenarier.Resultat indikerar att hybridmetoden, ungefär 61% RBAC och 39% ABAC, presterar mycket bättre än implementeringen av ren ABAC eller ren RBAC. Det minskar antalet intrångsfrekvensen med 16% jämfört med ren ABAC och 05% jämfört med ren RBAC, och utnyttjar de strukturerade kontrollerna av RBAC vid sidan av den kontextkänsliga anpassningsförmågan hos ABAC.

Forskningen visar att åtkomstkontroll kan optimeras strategiskt genom att använda förutseende tillvägagångssätt för motståndares beteende, vilket minskar svarstiden på potentiella hot.

Abstract [en]

This paper discusses one such novel approach to the optimal design of access policies using the principles of game theory to balance the dynamics between Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC). It models the policy design process as the strategic interaction between attackers and defenders using Nash Equilibrium analysis to determine an optimal policy blend that improves security.

The approach is grounded in empirical statistics based on the IBM Cost of a Data Breach Report 2024 that provides detailed statistics of the average costs. And also based on success rates of common cyber attacks such as Phishing and Token Theft. The success rates were derived from two simulations environments. These statistics are used to estimate realistic payoff matrices, which are then utilized to compute the Nash Equilibrium.

The findings are then supported using agent-based simulations based on the Mesa framework, where the performance of policy settings can be observed under dynamic scenarios.

Outcomes indicate that the hybrid approach 61% RBAC and 39% ABAC, performs much better than the implementation of pure ABAC or pure RBAC. It decreases breach rates by 16% compared to pure ABAC and by 05% compared to pure RBAC, leveraging the structured controls of RBAC alongside the context-sensitive adaptability of ABAC.

The research shows that access control can be strategically optimized using anticipatory approaches to adversary behavior, decreasing response time to potential threats.

Place, publisher, year, edition, pages
2025. , p. 38
Keywords [en]
ABAC, Cybersecurity, Matplotlib, Mesa, Nash equilibrium, Nashpy, Phishing, RBAC, Simulation, Token Theft
National Category
Computer Systems
Identifiers
URN: urn:nbn:se:hv:diva-24252Local ID: EHD500OAI: oai:DiVA.org:hv-24252DiVA, id: diva2:2000182
Subject / course
Computer engineering
Educational program
Datateknik - högskoleingenjör
Supervisors
Examiners
Available from: 2025-09-30 Created: 2025-09-23 Last updated: 2025-09-30Bibliographically approved

Open Access in DiVA

fulltext(1295 kB)196 downloads
File information
File name FULLTEXT01.pdfFile size 1295 kBChecksum SHA-512
0527bec0baa679f38eac1237df9001c0e2eb816d453a135819f076b9a7affcef235672d775ce5b2f5a5ec26e34c205cbd0c29252d879b837dcde656ade4b0ac0
Type fulltextMimetype application/pdf

By organisation
Department of Engineering Science
Computer Systems

Search outside of DiVA

GoogleGoogle Scholar
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 1021 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf