RAFIA: A Game-Theoretic Risk-Based Framework for Insider Threat Mitigation

PDF (1804KB), PP.197-232

Views: 0 Downloads: 0

Author(s)

Hala Yousif Mohamed Ahmed 1,* Mohamed Mejri 2

1. College of Computer Science and Information Technology, Sudan University of Science and Technology, Khartoum, 11111, Sudan

2. Department of Computer Science and Software Engineering, Universite´ Laval, Quebec, G1V 0A6, Canada

* Corresponding author.

DOI: https://doi.org/10.5815/ijwmt.2026.04.12

Received: 5 Jun. 2026 / Revised: 24 Jun. 2026 / Accepted: 17 Jul. 2026 / Published: 8 Aug. 2026

Index Terms

Access control, Insider threats, Risk-based access control, Game-theoretic access control, Linear Temporal Logic, Risk-LTL

Abstract

Insider attacks pose a significant security threat precisely because they originate from individuals with authorized access, making them inherently difficult to detect and prevent; addressing this issue is crucial for preserving the confidentiality, integrity, and availability of organizational systems. This paper contributes to mitigating insider attacks by proposing an approach called RAFIA, which monitors the system, evaluates the risk of insider threats, and blocks malicious actions before unauthorized or high-risk access is granted. The security policy is specified using an enhanced version of Linear Temporal Logic, called Risk-LTL, which evaluates the risk of each new action based on system history, including log files or traces, and a risk evaluation function provided as input. Risk evaluation is based on combining maliciousness probability and impact assessment, enabling quantitative estimation of the risk associated with user actions and action traces. Access decisions are governed by configurable risk thresholds specified within Risk-LTL policies. To strengthen decision-making, the model frames access control as a game between users and the organization. By applying game-theoretic tools, the system analyzes user behavior and makes access decisions that discourage malicious actions and reward honest ones. The objective is to reach a Nash equilibrium, where both players act rationally and securely. The proposed approach aims to improve the effectiveness of access control by reducing dishonest behavior and promoting more stable, risk-aware system interactions. Experimental evaluation using synthetic workloads of up to 10,000 access requests demonstrated the practicality of the proposed framework. RAFIA achieved an average authorization latency of approximately 3.3 ms while improving the F1-score compared with a conventional static-threshold access-control baseline.

Cite This Paper

Hala Yousif Mohamed Ahmed, Mohamed Mejri, "RAFIA: A Game-Theoretic Risk-Based Framework for Insider Threat Mitigation", International Journal of Wireless and Microwave Technologies(IJWMT), Vol.16, No.4, pp. 197-232, 2026. DOI:10.5815/ijwmt.2026.04.12

Reference

[1]M. Stamp, Information Security: Principles and Practice, 3rd ed. John Wiley & Sons, 2021.
[2]Verizon, “Data Breach Investigations Report.” 2024. Accessed: Jun. 03, 2025. [Online]. Available: https://www.verizon.com/business/resources/reports/dbir/.
[3]“2024 Insider Threat Report.” Accessed: Jun. 20, 2025. [Online]. Available: https://www.cybersecurity-insiders.com/2024-insider-threat-report/
[4]Exabeam, “2025 Insider Threat Report: From Humans to AI Agents.” 2025. Accessed: Jun. 20, 2025. [Online]. Available: https://www.exabeam.com/
[5]Ponemon Institute, “Cost Of Insider Risks Global Report,” Ponemon Institute, 2023. Accessed: Jun. 03, 2025. [Online]. Available: https://ponemonsullivanreport.com/2023/10/cost-of-insider-risks-global-report-2023.
[6]Gartner, “Cybersecurity Insights & Solutions for CISOs & Leaders.” 2023. Accessed: Jul. 01, 2026. [Online]. Available: https://www.gartner.com/en/cybersecurity
[7]National Institute of Standards and Technology (Corporate Author), “Security and Privacy Controls for Information Systems and Organizations,” National Institute of Standards and Technology, Gaithersburg, MD, USA, Special Publication 800-53 Revision 5, 2020. doi: 10.6028/NIST.SP.800-53r5.
[8]V. Suhendra, “A Survey on Access Control Deployment,” in Communications in Computer and Information Science, vol. 259, T. Kim, H. Adeli, W. Fang, J. G. Villalba, K. P. Arnett, and M. K. Khan, Eds., Berlin/Heidelberg, Germany: Springer, 2011, pp. 11–20.
[9]P.-C. Cheng, et al., “Fuzzy multi-level security: An experiment on quantified risk-adaptive access control,” in 2007 IEEE Symposium on Security and Privacy (SP’07), IEEE, 2007, pp. 222–230. doi: 10.1109/SP.2007.21.
[10]R. A. Shaikh, K. Adi, and L. Logrippo, “Dynamic risk-based decision methods for access control systems,” Comput. Secur., vol. 31, no. 4, pp. 447–464, 2012, doi: 10.1016/j.cose.2012.02.006.
[11]Díaz-López, Daniel, Dólera-Tormo, Ginés, Félix Gómez-Mármol, and Gregorio Martínez-Pérez, “Dynamic Counter-Measures for Risk-Based Access Control Systems: An Evolutive Approach,” Future Gener. Comput. Syst., vol. 55, pp. 321–335, 2016, doi: https://doi.org/10.1016/j.future.2014.10.012.
[12]C. Perera, A. Zaslavsky, P. Christen, and D. Georgakopoulos, “Context aware computing for the internet of things: A survey,” IEEE Commun. Surv. Tutor., vol. 16, no. 1, pp. 414–454, 2013, doi: 10.1109/SURV.2013.042313.00197.
[13]H. Ding, C. Peng, Y. Tian, and S. Xiang, “A Game Theoretical Analysis of Risk Adaptive Access Control for Privacy Preserving,” in 2019 International Conference on Networking and Network Applications (NaNA), IEEE, 2019, pp. 253–258. doi: 10.1109/NaNA.2019.00052.
[14]Lei Zhang; A. Brodsky; S. Jajodia, “Toward information sharing: benefit and risk access control (BARAC),” in Proceedings of the Seventh IEEE International Workshop on Policies for Distributed Systems and Networks (POLICY’06), IEEE Computer Society, 2006, pp. 9–17. doi: 10.1109/POLICY.2006.36.
[15]L. Pokorádi, “Application of fuzzy set theory for risk assessment,” J. KONBiN, vol. 14, no. 1, pp. 187–196, 2010.
[16]H. F. Atlam, M. A. Azad, M. O. Alassafi, A. A. Alshdadi, and A. Alenezi, “Risk-Based Access Control Model: A Systematic Literature Review,” Future Internet, vol. 12, no. 6, p. 103, 2020, doi: 10.3390/fi12060103.
[17]D. Akinwumi, G. Iwasokun, B. Alese, and S. Oluwadare, “A review of game theory approach to cyber security risk management,” Niger. J. Technol., vol. 36, no. 4, pp. 1271–1285, 2017, doi: 10.4314/njt.364.1502.
[18]Y. Wang, L. Tian, and Z. Chen, “Game Analysis of Access Control Based on User Behavior Trust,” Information, vol. 10, no. 4, p. 132, 2019, doi: 10.3390/info10040132.
[19]Office of the Privacy Commissioner of Canada, “Combination of weaknesses led to massive data breach at Desjardins.” Accessed: Jun. 23, 2026. [Online]. Available: https://www.priv.gc.ca/en/opc-news/news-and-announcements/2020/nr-c_201214/.
[20]F. L. Greitzer, L. J. Kangas, C. F. Noonan, R. E. Hohimer, and A. C. Dalton, “Identifying At-Risk Employees: Modeling Psychosocial Precursors of Potential Insider Threats,” in 2012 45th Hawaii International Conference on System Sciences, Maui, HI, USA: IEEE, Jan. 2012, pp. 2392–2401. doi: 10.1109/HICSS.2012.309.
[21]S. Tadelis, Game Theory: An Introduction. Princeton, NJ: Princeton University Press, 2013.
[22]E. Ho, A. Rajagopalan, A. Skvortsov, S. Arulampalam, and M. Piraveenan, “Game Theory in Defence Applications: A Review,” Sensors, vol. 22, no. 3, p. 1032, 2022, doi: 10.3390/s22031032.
[23]A. K. Malik et al., “From Conventional to State-of-the-Art IoT Access Control Models,” Electronics, vol. 9, no. 10, p. 1693, 2020, doi: 10.3390/electronics9101693.
[24]K. Ma, G. Yang, and Y. Xiang, “RCBAC: A risk-aware content-based access control model for large-scale text data,” J. Netw. Comput. Appl., vol. 167, p. 102733, 2020, doi: 10.1016/j.jnca.2020.102733.
[25]D. R. Dos Santos, C. M. Westphall, and C. B. Westphall, “A dynamic risk-based access control architecture for cloud computing,” in 2014 IEEE Network Operations and Management Symposium (NOMS), IEEE, 2014, pp. 1–9. doi: 10.1109/NOMS.2014.6838319.
[26]B. M. Babu and M. S. Bhanu, “Prevention of insider attacks by integrating behavior analysis with risk based access control model to protect cloud,” Procedia Comput. Sci., vol. 54, pp. 157–166, 2015, doi: 10.1016/j.procs.2015.06.018.
[27]Y. Li, H. Sun, Z. Chen, J. Ren, and H. Luo, “Using trust and risk in access control for grid environment,” in 2008 International Conference on Security Technology, IEEE, 2008, pp. 13–16. doi: 10.1109/SecTech.2008.50.
[28]R. McGraw, “Risk-adaptable access control (radac),” in Privilege (Access) Management Workshop. NIST–National Institute of Standards and Technology–Information Technology Laboratory, 2009, pp. 55–58.
[29]R. A. Shaikh, K. Adi, L. Logrippo, and S. Mankovski, “Risk-based decision method for access control systems,” in 2011 Ninth Annual International Conference on Privacy, Security and Trust, IEEE, 2011, pp. 189–192. doi: 10.1109/PST.2011.5971982.
[30]L. Rajbhandari and E. A. Snekkenes, “Using game theory to analyze risk to privacy: An initial insight,” in IFIP PrimeLife International Summer School on Privacy and Identity Management for Life, Springer, 2010, pp. 41–51. doi: 10.1007/978-3-642-20769-3_4.
[31]N. N. Diep, et al., “Enforcing access control using risk assessment,” in Fourth European Conference on Universal Multiservice Networks (ECUMN’07), IEEE, 2007, pp. 419–424. doi: 10.1109/ECUMN.2007.19.
[32]N. Metoui, M. Bezzi, and A. Armando, “Trust and risk-based access control for privacy preserving threat detection systems,” in International Conference on Future Data and Security Engineering, Springer, 2016, pp. 285–304. doi: 10.1007/978-3-319-48057-2_20.
[33]H. Khambhammettu, S. Boulares, K. Adi, and L. Logrippo, “A framework for risk assessment in access control systems,” Comput. Secur., vol. 39, pp. 86–103, 2013, doi: 10.1016/j.cose.2013.03.010.
[34]M. Sharma, Y. Bai, S. Chung, and L. Dai, “Using risk in access control for cloud-assisted ehealth,” in 2012 IEEE 14th International Conference on High Performance Computing and Communication & 2012 IEEE 9th International Conference on Embedded Software and Systems, IEEE, 2012, pp. 1047–1052. doi: 10.1109/HPCC.2012.153.
[35]H. F. Atlam, R. J. Walters, G. B. Wills, and J. Daniel, “Fuzzy logic with expert judgment to implement an adaptive risk-based access control model for IoT,” Mob. Netw. Appl., pp. 1–13, 2019, doi: 10.1007/s11036-019-01214-w.
[36]F. K. Dankar and R. Badji, “A risk-based framework for biomedical data sharing,” J. Biomed. Inform., vol. 66, pp. 231–240, 2017, doi: 10.1016/j.jbi.2017.01.012.
[37]M. Abomhara, G. M. Køien, V. A. Oleshchuk, and M. Hamid, “Towards Risk-aware Access Control Framework for Healthcare Information Sharing.,” in ICISSP, 2018, pp. 312–321. doi: 10.5220/0006608103120321.
[38]C. A. B. De Carvalho, R. M. de Castro Andrade, N. Agoulmine, and M. F. de Castro, “Detection of Access Control Violations in the Secure Sharing of Cloud Storage.,” in CLOSER, 2018, pp. 124–135. doi: 10.5220/0006698701240135.
[39]P. A. Evina, F. L. Ayachi, F. Jaidi, and A. Bouhoula, “Anomalies Correlation for Risk-Aware Access Control Enhancement.,” in ENASE, 2018, pp. 299–304. doi: 10.5220/0006766802990304.
[40]X. Chen, “Risk-based Access Control Model for Hospital Information Systems,” Front. Comput. Intell. Syst., 2023, doi: 10.54097/fcis.v2i3.5315.
[41]M. N. Nobi, R. Krishnan, Y. Huang, M. Shakarami, and R. Sandhu, “Toward Deep Learning Based Access Control,” in Proceedings of the Twelfth ACM Conference on Data and Application Security and Privacy, in CODASPY ’22. ACM, 2022, pp. 143–154. doi: 10.1145/3508398.3511497.
[42]J. Yin, et al., “A Heterogeneous Graph-Based Semi-Supervised Learning Framework for Access Control Decision-Making,” World Wide Web, vol. 27, no. 4, p. 35, 2024, doi: 10.1007/s11280-024-01275-2.
[43]S. Yarram, N. Dasari, S. B. Seshagani, and P. Ganguly, “Privacy-Preserving Healthcare Data Security Using Large Language Models and Adaptive Access Control,” in 2025 IEEE World AI IoT Congress (AIIoT), 2025. doi: 10.1109/AIIoT65859.2025.11105296.