Safeguarding Social Networks: A Location-Aware Approach to Attribute-Based Access Control

Specification and Enforcement of Location-Aware Attribute-Based Access Control for Online Social Networks

2016-03-08
Andy Chunliang Hsu, Indrakshi Ray
Summary
Problem
Method
Results
Takeaways
Abstract

The paper proposes a "Location-Aware Attribute-Based Access Control" (LA-ABAC) model for Online Social Networks (OSNs) to mitigate risks of stolen credentials. By integrating geolocation data into the NIST Policy Machine framework, it authenticates users by correlating their current IP-based location with historical "geographical footprints" extracted from past social media activity.

TL;DR

As Online Social Networks (OSNs) become repositories for nearly every aspect of our personal lives, the risk of credential theft grows. This paper introduces a Location-Aware Attribute-Based Access Control (LA-ABAC) model. Rather than just checking who you are (password), it checks where you are based on your historical behavior. By extending the NIST Policy Machine with "Location Containers," the system calculates a confidence score that can thwart attackers even if they have your login credentials.

The Motivation: When Passwords Aren't Enough

Online Social Networks are currently dominated by Relationship-Based Access Control (ReBAC)—the idea that if you are a "Friend," you can see my photos. However, ReBAC does nothing to stop an attacker who has stolen a user's password.

Existing solutions like simple IP whitelisting are too rigid for modern life. Users travel, move between cities, and post from new cafes. The authors identified a need for a system that is:

  1. Dynamic: It adapts as the user moves.
  2. Context-Aware: It looks at the "where" and "when" of an access request.
  3. Probabilistic: It understands that a "new" location near an "old" one is less suspicious than a login from across the globe.

Methodology: Location as a First-Class Attribute

The core innovation lies in bridging the gap between NIST Policy Machine (PM) and Geospatial Data.

1. Extending NIST Policy Machine

In a standard PM, access is determined by user and object "containers." The authors added Location Containers.

  • User-Location Association: If Jane often posts from Fort Collins, she is assigned to the "Fort Collins" location container.
  • Environmental Constraints: Permissions are augmented with spatial constraints. An "Access Location" container ensures that the user is physically where their profile says they should be.

Using PM to Represent OSN Policies

2. The Confidence Evaluation Formula

How do we decide if a location is "reasonable"? The authors propose a Confidence Score ():

  • Quality Score (): Measures proximity. If you are 5 miles from a previous post, is high (0.9). If you are 35 miles away, drops to 0.
  • Quantity Value (): Measures frequency. If 30% of your total posts came from this area, the system is very confident that it’s you.

3. Geocode Correlation Process

When a user logs in, the system grabs their IP, converts it to a Geocode (lat/long), and creates a Postal Code Range Zone. It then queries the user's history (R_geo) to find spatial matches within that zone.

Postal Code Range Zone

Experiments: Real-World Scenarios

The authors built a test bed using Elgg (an open-source social engine). They tested three key scenarios:

ScenarioLocationHistory MatchResult
Legitimate UserNew city, nearbyHigh ProximityAccess Granted ()
Atypical LoginFurther awayLow Proximity/Low CountAccess Denied ()
AttackerOut of StateNo HistoryAccess Denied ()

User Access Denied Example

Critical Insight & Future Outlook

The beauty of this approach is its use of passive metadata. The user doesn't have to do anything; their past activity (geotagged photos, check-ins) builds the security model for them.

However, there are limitations:

  • Privacy: Building a database of every user's location history (R_geo) creates a massive target for hackers. The "protector" must be a "vigilant steward" of this metadata.
  • Cold Start: What happens to a new user with zero posts? The paper suggests falling back to additional authentication (like 2FA).

Conclusion: This paper moves OSN security away from static "who-you-know" relationships toward a multi-dimensional "how-you-behave" model. By integrating location into the NIST PM framework, it provides a blueprint for an ABAC standard that could eventually secure everything from Facebook to the Internet of Things (IoT).

Find Similar Papers

Try Our Examples

  • Search for recent papers that extend the NIST Policy Machine with more complex environmental attributes such as temporal patterns or device biometric signatures.
  • Which 2011-2015 papers first established Relationship-Based Access Control (ReBAC) as the standard for OSNs, and how did they handle privacy settings misconfigurations?
  • What are the current SOTA methods for IP geolocation accuracy in mobile cellular networks compared to the database-driven approach used in this paper?
Contents
Safeguarding Social Networks: A Location-Aware Approach to Attribute-Based Access Control
1. TL;DR
2. The Motivation: When Passwords Aren't Enough
3. Methodology: Location as a First-Class Attribute
3.1. 1. Extending NIST Policy Machine
3.2. 2. The Confidence Evaluation Formula
3.3. 3. Geocode Correlation Process
4. Experiments: Real-World Scenarios
5. Critical Insight & Future Outlook