Work place: College of Computer Science and Information Technology, Sudan University of Science and Technology, Khartoum, 11111, Sudan
E-mail: halaahmed043@hotmail.com
Website: https://orcid.org/0000-0002-4727-0337
Research Interests: Internet of Things
Biography
Hala Yousif Mohamed Ahmed is currently pursuing a Ph.D. in Computer Science. She received her B.Sc. (Honours) and M.Sc. degrees in Computer Science from the University of Khartoum, Sudan. Her research interests include cybersecurity, Internet of Things (IoT) security, AI-driven threat detection, game theory, and risk-aware access control.
By Hala Yousif Mohamed Ahmed Mohamed Mejri
DOI: https://doi.org/10.5815/ijwmt.2026.04.12, Pub. Date: 8 Aug. 2026
Insider attacks pose a significant security threat precisely because they originate from individuals with authorized access, making them inherently difficult to detect and prevent; addressing this issue is crucial for preserving the confidentiality, integrity, and availability of organizational systems. This paper contributes to mitigating insider attacks by proposing an approach called RAFIA, which monitors the system, evaluates the risk of insider threats, and blocks malicious actions before unauthorized or high-risk access is granted. The security policy is specified using an enhanced version of Linear Temporal Logic, called Risk-LTL, which evaluates the risk of each new action based on system history, including log files or traces, and a risk evaluation function provided as input. Risk evaluation is based on combining maliciousness probability and impact assessment, enabling quantitative estimation of the risk associated with user actions and action traces. Access decisions are governed by configurable risk thresholds specified within Risk-LTL policies. To strengthen decision-making, the model frames access control as a game between users and the organization. By applying game-theoretic tools, the system analyzes user behavior and makes access decisions that discourage malicious actions and reward honest ones. The objective is to reach a Nash equilibrium, where both players act rationally and securely. The proposed approach aims to improve the effectiveness of access control by reducing dishonest behavior and promoting more stable, risk-aware system interactions. Experimental evaluation using synthetic workloads of up to 10,000 access requests demonstrated the practicality of the proposed framework. RAFIA achieved an average authorization latency of approximately 3.3 ms while improving the F1-score compared with a conventional static-threshold access-control baseline.
[...] Read more.Subscribe to receive issue release notifications and newsletters from MECS Press journals