G-SIR: Hardening Access Control with Geo-Social Intelligence to Deter Insider Attacks
G-SIR: An Insider Attack Resilient Geo-Social Access Control Framework
The paper introduces G-SIR (Geo-Social Insider Threat Resilient Access Control), a novel framework that integrates current and historical geo-social context into Role-Based Access Control (RBAC). It leverages location data and social relationships to identify suspicious behavior and mitigate insider attacks in organizational environments.
TL;DR
The G-SIR framework redefines organizational security by treating a user's physical location and social network as real-time security signals. Unlike traditional systems that only check "who you are," G-SIR checks "where you've been," "who is standing next to you," and "if your current companions are likely to collude with you." This approach captures 33% more insider threats than existing geo-aware baselines.
Background: The Invisible Threat Within
Insider attacks are the most "expensive" category of cybercrime because the attackers already hold the keys to the kingdom. Prior work in Geo-Social Access Control (like Geo-Social RBAC) focused on location-based permissions but was fundamentally "blind" to behavioral red flags. If a user didn't request access while in a restricted area, the system wouldn't notice. G-SIR changes this by creating a continuous behavioral audit.
Methodology: The Four Pillars of G-SIR
G-SIR extends the standard Role-Based Access Control (RBAC) with four sophisticated geo-social hooks:
- Geo-Social Contracts: Defines "forbidden zones" and "forbidden acquaintances" for specific roles. Violation reduces a user's trust score even if no data is accessed.
- Vicinity Constraints: Categorizes nearby users into Enablers (trusted parties who browse with you) or Inhibitors (competitors or unauthorized observers who trigger an automatic deny to prevent data leakage).
- Geo-Social Traces: Implements a "protocol of movement." For example, a doctor must pass through a sanitization station (Place A) before accessing the Neo-natal Unit (Place B).
- Collusion-Free Enforcement: A critical innovation that calculates the probability of collusion between a requester and their enablers. If the group is too "tight-knit" in a suspicious context, access is revoked.
The G-SIR Architecture integrates Monitoring, Context Inference, and an Adaptive Policy Decision Point (PDP).
Risk Management: Decision Under Uncertainty
A highlight of G-SIR is its Utility-Based Risk Management. Instead of a binary "Yes/No," it uses a mathematical framework:
By comparing the expected utility of granting access versus denying it (considering the probability of an attack ), G-SIR can make high-stakes decisions—like granting emergency file access to a doctor in a hospital while denying that same doctor access from a public cafe.
Experimental Insights
The authors validated G-SIR via discrete indoor simulations. Key findings include:
- Baseline Superiority: G-SIR caught significantly more threats than Geo-Social RBAC, particularly in detecting suspicious requesters and collusion.
- Proximity Attack Mitigation: As the number of "inhibiting users" (people who shouldn't see the data) increased, G-SIR's detection rate for confidentiality leaks scaled effectively.
- Resilience: The system remains effective even with "noisy" data. Even if the attack probability estimation has high error, the policy constraints act as a secondary safety net.
G-SIR identifies 4 new categories of violations (Suspicious Requester, Inhibiting Users, Colluding Users, and Contract Violations) that previous models ignored.
Conclusion & Future Outlook
G-SIR represents a shift from Identity Management to Behavioral Integrity. While it requires robust indoor positioning (like BLE or Wi-Fi triangulation), its ability to bake social context into the very heart of the access decision is a major leap forward for high-security environments like government labs and financial institutions.
Future Direction: The framework assumes a reliable location service. Future research must address "location spoofing" attacks where malicious insiders attempt to manipulate their perceived geo-social context to bypass these constraints.
