TAC: Hybrid IAM Privilege Escalation Detection
The paper presents TAC, a novel hybrid IAM privilege escalation detection framework for AWS that combines a comprehensive whitebox detector with an innovative, reinforcement-learning-driven greybox approach to identify permission flow-based attacks while respecting customer privacy constraints.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Imagine the internet as a giant, bustling city where every building, bank, and secret vault is protected by a digital doorman. This doorman is called Identity and Access Management, or IAM for short. Its job is simple but critical: it decides who gets to walk through which doors. If the doorman makes a mistake—like giving a janitor the keys to the CEO's safe or letting a delivery driver open the bank vault—that's a "misconfiguration." In the world of cloud computing, these mistakes are like leaving the front door wide open for thieves, leading to data breaches and stolen secrets. For years, security experts have built tools to check these doormen, but they've faced two big problems: their tools only know how to spot a few specific types of mistakes, and they demand to see the entire, secret list of keys and rules before they can even start looking. This means many dangerous mistakes slip through the cracks, and companies are often too scared to share their full security blueprints with outsiders.
Enter a new team of researchers who built a smarter, more flexible security guard named TAC. Think of TAC as a hybrid detective that can work in two different modes. First, there's TAC-WB, the "Whitebox" detective. This one is like a master locksmith who gets to see every single blueprint, key, and rule in the building. By studying over 14,000 different ways permissions can be passed around, TAC-WB created a massive "cheat sheet" of 219 different ways a thief could sneak in. It uses this sheet to trace every possible path a permission could take, ensuring it catches every type of privilege escalation, even the tricky ones other tools miss.
But what if the building owner refuses to hand over the blueprints? That's where TAC-GB, the "Greybox" detective, comes in. This is the paper's real magic trick. Instead of demanding the whole map, TAC-GB plays a smart game of "20 Questions." It looks at the parts of the map the owner is willing to share and then asks very specific, targeted questions like, "Does this user have this specific key?" The owner can say "Yes," "No," or "I'd rather not say." TAC-GB is so clever that it uses a special kind of artificial intelligence (a brain that learns from graphs) to figure out exactly which questions will reveal the most secrets with the fewest tries. It's like a detective who knows exactly which door to knock on to find the thief, rather than knocking on every door in the neighborhood.
The researchers tested their new detectives against a mountain of fake and real-world security puzzles. They built a giant practice ground called TAC-Bench with 2,500 different scenarios to make sure their tools were ready for the real thing. The results were impressive: the Whitebox detective found every single mistake, including real-world attacks that caused massive data leaks, while older tools failed to spot them. Even more surprisingly, the Greybox detective, working with only partial information and asking just a handful of questions, performed almost as well as the tools that saw everything. It proved that you don't need to see the whole secret to catch the thief; you just need to ask the right questions. This new approach offers a way for companies to keep their secrets safe while still getting top-tier security checks, changing the game from "show us everything or nothing" to a smart, privacy-friendly partnership.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.