Optimizing Access Control Policies Using Game Theory: A Nash Equilibrium Approach
2025 (English)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE credits
Student thesis
Abstract [sv]
Den här artikeln diskuterar en ny metod för optimal utformning av åtkomst policyer med hjälp av spelteorins principer för att balansera dynamiken mellan rollbaserad åtkomstkon-troll (RBAC) och attributbaserad åtkomstkontroll (ABAC). Den modellerar policydesign processen som den strategiska interaktionen mellan angripare och försvarare med hjälp av Nash Equilibrium analys för att fastställa en optimal policyablandning som förbättrar säker-heten.
Projektet är baserat på empirisk statistik från IBM Cost of a Data Breach Report 2024 som ger detaljerad statistik över kostnaden. Det är också baserat på framgångsfrekvenser för vanliga cyberattacker som Phishing och Token Theft. Dessa framgångsfrekvenser härleddes från två simuleringsmiljöer. Denna statistik används för att uppskatta realistiska utbetalningsmatriser, som sedan används för att beräkna Nash Equilibrium.
Resultaten stöds sedan med hjälp av agentbaserade simuleringar baserade på Mesa-ramverket, där prestanda för policyinställningar kan observeras under dynamiska scenarier.Resultat indikerar att hybridmetoden, ungefär 61% RBAC och 39% ABAC, presterar mycket bättre än implementeringen av ren ABAC eller ren RBAC. Det minskar antalet intrångsfrekvensen med 16% jämfört med ren ABAC och 05% jämfört med ren RBAC, och utnyttjar de strukturerade kontrollerna av RBAC vid sidan av den kontextkänsliga anpassningsförmågan hos ABAC.
Forskningen visar att åtkomstkontroll kan optimeras strategiskt genom att använda förutseende tillvägagångssätt för motståndares beteende, vilket minskar svarstiden på potentiella hot.
Abstract [en]
This paper discusses one such novel approach to the optimal design of access policies using the principles of game theory to balance the dynamics between Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC). It models the policy design process as the strategic interaction between attackers and defenders using Nash Equilibrium analysis to determine an optimal policy blend that improves security.
The approach is grounded in empirical statistics based on the IBM Cost of a Data Breach Report 2024 that provides detailed statistics of the average costs. And also based on success rates of common cyber attacks such as Phishing and Token Theft. The success rates were derived from two simulations environments. These statistics are used to estimate realistic payoff matrices, which are then utilized to compute the Nash Equilibrium.
The findings are then supported using agent-based simulations based on the Mesa framework, where the performance of policy settings can be observed under dynamic scenarios.
Outcomes indicate that the hybrid approach 61% RBAC and 39% ABAC, performs much better than the implementation of pure ABAC or pure RBAC. It decreases breach rates by 16% compared to pure ABAC and by 05% compared to pure RBAC, leveraging the structured controls of RBAC alongside the context-sensitive adaptability of ABAC.
The research shows that access control can be strategically optimized using anticipatory approaches to adversary behavior, decreasing response time to potential threats.
Place, publisher, year, edition, pages
2025. , p. 38
Keywords [en]
ABAC, Cybersecurity, Matplotlib, Mesa, Nash equilibrium, Nashpy, Phishing, RBAC, Simulation, Token Theft
National Category
Computer Systems
Identifiers
URN: urn:nbn:se:hv:diva-24252Local ID: EHD500OAI: oai:DiVA.org:hv-24252DiVA, id: diva2:2000182
Subject / course
Computer engineering
Educational program
Datateknik - högskoleingenjör
Supervisors
Examiners
2025-09-302025-09-232025-09-30Bibliographically approved