Federated Identity Attack Path Discovery in Cross-Platform Access Control Systems
PDF

Keywords

Cloud identity security
federated identity risk
SSO vulnerability assessment
policy-based risk scoring
privileged access
cloud data governance
identity path analysis

Abstract

Federated identity and single sign-on systems are central to cloud data access control, but misconfigured trust relationships and vulnerable identity components may create hidden paths to sensitive resources. Conventional vulnerability scanners often report identity-provider and access-portal weaknesses separately, without measuring their combined impact on cloud data security. This study proposes a policy-based risk assessment framework for vulnerable federated identity paths in cloud environments. The framework models identity providers, SSO applications, trust policies, role mappings, conditional access rules, privileged sessions, and data-service permissions as an identity-risk graph. Vulnerability severity is combined with trust breadth, role elevation potential, session lifetime, authentication policy strength, privileged data access, and policy violations. Experiments are conducted on a federated cloud identity environment containing 12 identity providers, 1,860 SSO applications, 74,500 user-role mappings, 9,300 privileged roles, 4,280 conditional access rules, and 17,600 vulnerability records from access portals, identity connectors, and authentication services. The proposed method discovers 1,570 vulnerable identity-to-data paths, including weakly protected privileged roles, excessive SSO role mappings, outdated identity connectors, and long-lived sessions with access to sensitive databases. It consolidates 17,600 vulnerability findings into 2,140 identity-path remediation units. The graph engine evaluates 86,000 trust and permission edges in 238 seconds and completes incremental identity-policy updates in 27 seconds. After two remediation batches, privileged data-access paths affected by vulnerable identity components decrease from 1,570 to 514. The median analyst decision time drops from 13.2 minutes to 5.6 minutes per identity-risk case. These findings indicate that policy-based identity-path assessment can connect vulnerability management with cloud data-access governance and reduce hidden risks in federated identity systems.

PDF

References

Yin, J., Huang, Y., & Rao, H. (2026). A Study on User Behavior Signal-Driven Predictive Models for Digital Platform Consumption Trends. Available at SSRN 6607298.

Kushwaha, V. K., Verma, D. K., Yadav, S. P., & Gupta, H. (2026). Energy-Aware Federated Learning for IoT Intrusion Detection Using Latent Feature Encoding. IEEE Access.

Bari, B. S., Puthal, D., & Yelamarthi, K. (2025). Datasets in vehicular communication systems: A review of current trends and future prospects. SN Computer Science, 6(3), 210.

Zhang, Z. (2026). A Study on the Identification of Manipulative Design in Subscription and Payment Interfaces of Digital Consumer Platforms and Its Behavioral Effects. Available at SSRN 6734760.

Kiliç, C., & Şengül, G. (2026). SHAP-Guided Feature Selection for Cross-Dataset Generalization in Network Intrusion Detection Systems. IEEE Access.

Yang, J. (2026). Computational Analysis of How Digital Non-Clinical Communication Tools Influence Social Participation Among Older Adults in Community-Based Elderly Care. Available at SSRN 6682838.

Taheri, R., Gegov, A., Arabikhan, F., Ichtev, A., & Georgieva, P. (2025, November). Explainable Artificial Intelligence for Intrusion Detection in Connected Vehicles. In Principle and Practice of Data and Knowledge Acquisition Workshop (pp. 162-176). Singapore: Springer Nature Singapore.

Li, Y., & Liu, S. (2026, May). A Study on Dynamic Optimization of Alerting Policies and Multi-Agent Decision-Making Mechanisms in Cloud Environments. In 2026 7th International Seminar on Artificial Intelligence, Networking and Information Technology (AINIT) (pp. 703-706). IEEE.

Ibrahim, N., Rajalakshmi, N. R., Sivakumar, V., & Sharmila, L. (2025). An optimized hybrid ensemble machine learning model combining multiple classifiers for detecting advanced persistent threats in networks. Journal of Big Data, 12(1), 212.

Zhao, J., Fan, J., & Li, L. (2026). A Study on an Explainable Causal-Enhanced LLM Agent for Predicting the Forming Quality of Automotive Component Materials.

Shahin, M., Hosseinzadeh, A., & Chen, F. F. (2025). A Two-Stage Hybrid Federated Learning Framework for Privacy-Preserving IoT Anomaly Detection and Classification. IoT, 6(3), 48.

Xu, T., Zhu, W., & Zhang, J. (2026). A Study on the Application of Alternative Data in Credit Assessment for the Unbanked Population.

Aloqaily, A., Abdallah, E. E., Baarah, A., Alnabhan, M., Alshdaifat, E. A., & Milhem, H. (2025). Optimized Hybrid Ensemble Intrusion Detection for VANET-Based Autonomous Vehicle Security. Network, 5(4), 43.

Zhang, Z., Tong, Y., & Gao, Y. (2026). Retrieval-Augmented Generation with Low-Latency Deployment for Vertical Domains Question Answering: A Case Study on Economic Resource Platforms.

Rahman, M. H., Alnaeem, M., & Ibrahim, A. A. (2026). Detection of DSCP-based traffic prioritization manipulations and their impact on network performance. Scientific Reports.

Qi, C., & Qiao, X. (2026). Building and Operating a Large Scale Multi-Agent System: A Case Study from Industry. Available at SSRN 6795198.

Baharlouei, H., Makanju, A., & Zincir-Heywood, N. (2026). Comprehensive host-based malicious behaviour detection in vanets. Journal of Network and Systems Management, 34(4), 100.

Su, D., & Dong, Y. (2026). Classroom-Based Assessment with Bayesian Learning Analytics for Instructional Decision-Making in ASD Inclusive Education.

Huang, R. (2026). ConfSched: Confidence-Threshold Routing for Efficient Edge-Cloud Activity Recognition. World Journal of Engineering and Technology, 14(2), 471-486.

Nagar, S., Verma, K., Singh, S., & Shashvat, K. (2026). Modified ResNet-50 and custom CNN ensembles achieve near perfect STEMI detection on European ST-T database. Discover Artificial Intelligence.

Gao, G., Gao, R., Lu, C., Gao, R., & Kuang, Y. (2026, March). Security Governance Methods and Quantitative Evaluation for Enterprise SMS and Verification Code Systems. In 2026 International Conference on Generative Artificial Intelligence and Information Security (GAIIS) (pp. 455-458). IEEE.

Edo, G., Ahmad, T., & Putra, M. A. R. (2025). Hybrid GAN-LSTM for Enhancing DDoS Detection on Imbalance Dataset. International Journal of Safety & Security Engineering, 15(1).

Yan, B. (2026). Robust Day-Night Image Matching Across Extreme Illumination Variations: A Comparative Study of Deep Learning and Classical Methods. International Academic Journal of Engineering and Technology Science, 2, 65-72.

Moumen, I., El Makrani, A., Rafalia, N., & Abouchabaka, J. (2025, November). A Novel Hybrid XGB-RF BlendStack Model for Traffic Flow Prediction. In 2025 12th International Conference on Wireless Networks and Mobile Communications (WINCOM) (pp. 1-7). IEEE.

Feng, Y., Yang, Y. H., & Liao, T. (2026). Adaptive Task Scheduling for Edge Large Language Models Based on Multi-Source Sensing Context.

Sankar, S. R., & Jothi, B. (2026). EGOA-DL-IDS: explainable intrusion detection in SDN-based industrial cyber physical system with optimized deep learning techniques. Cluster Computing, 29(4), 242.

Liu, H., Xu, D., Ma, Q., Xu, S., & Qiu, D. (2026). Memory Poisoning Propagation and Repair Mechanism in Multi-Agent Collaborative Environments.

Sheelavant, K. K., Yamini, C., Bhushan, P., & Kumar, C. (2025). Ensemble Learning-Based Intrusion Detection and Classification for Securing IoT Networks: An Optimized Strategy for Threat Detection and Prevention. Journal of Intelligent Systems and Internet of Things, 101-118.

Jiao, Y., Zhao, B., Wang, A., & Shi, T. (2026). Construction and Empirical Study of a Modularized Teaching System for Art Courses Based on a Unified Training Pathway.