Resilient Risk based Adaptive Authentication and Authorization (RAD-AA) Framework
Jaimandeep Singh, Chintan Patel, Naveen Kumar Chaudhary

TL;DR
The paper introduces RAD-AA, a resilient, risk-based adaptive authentication and authorization framework that enhances security against credential theft and token manipulation by self-adapting based on risk scores and trust profiles, incorporating ML techniques.
Contribution
It proposes a novel resilient framework that adapts authentication and authorization processes based on risk assessments, improving security over existing standards like OAuth 2.0, OpenID Connect, and SAML 2.0.
Findings
Framework increases attack costs for adversaries
Resilience against common threat vectors demonstrated
ML-based risk scoring improves adaptive accuracy
Abstract
In recent cyber attacks, credential theft has emerged as one of the primary vectors of gaining entry into the system. Once attacker(s) have a foothold in the system, they use various techniques including token manipulation to elevate the privileges and access protected resources. This makes authentication and token based authorization a critical component for a secure and resilient cyber system. In this paper we discuss the design considerations for such a secure and resilient authentication and authorization framework capable of self-adapting based on the risk scores and trust profiles. We compare this design with the existing standards such as OAuth 2.0, OpenID Connect and SAML 2.0. We then study popular threat models such as STRIDE and PASTA and summarize the resilience of the proposed architecture against common and relevant threat vectors. We call this framework as Resilient Risk…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAccess Control and Trust · Information and Cyber Security · Cloud Data Security Solutions
