G-SIR: Hardening Access Control with Geo-Social Intelligence to Deter Insider Attacks

G-SIR: An Insider Attack Resilient Geo-Social Access Control Framework

2017-01-17
Nathalie Baracaldo, Balaji Palanisamy, James Joshi
Summary
Problem
Method
Results
Takeaways
Abstract

The paper introduces G-SIR (Geo-Social Insider Threat Resilient Access Control), a novel framework that integrates current and historical geo-social context into Role-Based Access Control (RBAC). It leverages location data and social relationships to identify suspicious behavior and mitigate insider attacks in organizational environments.

TL;DR

The G-SIR framework redefines organizational security by treating a user's physical location and social network as real-time security signals. Unlike traditional systems that only check "who you are," G-SIR checks "where you've been," "who is standing next to you," and "if your current companions are likely to collude with you." This approach captures 33% more insider threats than existing geo-aware baselines.

Background: The Invisible Threat Within

Insider attacks are the most "expensive" category of cybercrime because the attackers already hold the keys to the kingdom. Prior work in Geo-Social Access Control (like Geo-Social RBAC) focused on location-based permissions but was fundamentally "blind" to behavioral red flags. If a user didn't request access while in a restricted area, the system wouldn't notice. G-SIR changes this by creating a continuous behavioral audit.

Methodology: The Four Pillars of G-SIR

G-SIR extends the standard Role-Based Access Control (RBAC) with four sophisticated geo-social hooks:

  1. Geo-Social Contracts: Defines "forbidden zones" and "forbidden acquaintances" for specific roles. Violation reduces a user's trust score even if no data is accessed.
  2. Vicinity Constraints: Categorizes nearby users into Enablers (trusted parties who browse with you) or Inhibitors (competitors or unauthorized observers who trigger an automatic deny to prevent data leakage).
  3. Geo-Social Traces: Implements a "protocol of movement." For example, a doctor must pass through a sanitization station (Place A) before accessing the Neo-natal Unit (Place B).
  4. Collusion-Free Enforcement: A critical innovation that calculates the probability of collusion between a requester and their enablers. If the group is too "tight-knit" in a suspicious context, access is revoked.

G-SIR Architecture The G-SIR Architecture integrates Monitoring, Context Inference, and an Adaptive Policy Decision Point (PDP).

Risk Management: Decision Under Uncertainty

A highlight of G-SIR is its Utility-Based Risk Management. Instead of a binary "Yes/No," it uses a mathematical framework:

By comparing the expected utility of granting access versus denying it (considering the probability of an attack ), G-SIR can make high-stakes decisions—like granting emergency file access to a doctor in a hospital while denying that same doctor access from a public cafe.

Experimental Insights

The authors validated G-SIR via discrete indoor simulations. Key findings include:

  • Baseline Superiority: G-SIR caught significantly more threats than Geo-Social RBAC, particularly in detecting suspicious requesters and collusion.
  • Proximity Attack Mitigation: As the number of "inhibiting users" (people who shouldn't see the data) increased, G-SIR's detection rate for confidentiality leaks scaled effectively.
  • Resilience: The system remains effective even with "noisy" data. Even if the attack probability estimation has high error, the policy constraints act as a secondary safety net.

Threat Detection Results G-SIR identifies 4 new categories of violations (Suspicious Requester, Inhibiting Users, Colluding Users, and Contract Violations) that previous models ignored.

Conclusion & Future Outlook

G-SIR represents a shift from Identity Management to Behavioral Integrity. While it requires robust indoor positioning (like BLE or Wi-Fi triangulation), its ability to bake social context into the very heart of the access decision is a major leap forward for high-security environments like government labs and financial institutions.

Future Direction: The framework assumes a reliable location service. Future research must address "location spoofing" attacks where malicious insiders attempt to manipulate their perceived geo-social context to bypass these constraints.

Find Similar Papers

Try Our Examples

  • Search for recent papers that utilize Machine Learning or Graph Neural Networks to improve the accuracy of community detection and collusion prediction in insider threat mitigation.
  • Which research first introduced the concept of "Social Contracts" in computer security, and how does G-SIR formalize these contracts into a programmable access control logic?
  • Explore how the G-SIR framework's vicinity-based enabler/inhibitor logic can be extended to Zero Trust Architectures (ZTA) for securing remote work environments.
Contents
G-SIR: Hardening Access Control with Geo-Social Intelligence to Deter Insider Attacks
1. TL;DR
2. Background: The Invisible Threat Within
3. Methodology: The Four Pillars of G-SIR
4. Risk Management: Decision Under Uncertainty
5. Experimental Insights
6. Conclusion & Future Outlook