1
Return

Transforming IDS records into ABAC events for advancing reproducible access control research

delete2026-08-10
delete0
delete
OA
AI
R
Ricardo A. Ibarra-Garcia
A
Arturo Diaz-Perez *
J
J. L. González-Compeán
DOI:10.1016/j.cose.2026.105101delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Attribute-Based Access Control (ABAC) is a popular approach for organizations to enforce fine-grained policies for regulating interactions among human and/or AI agents with digital resources. However, the design and training of ABAC models rely on datasets based on access logs that capture interactions commonly containing sensitive information such as behavioral traces, contextual information, and resource/user identifiers. As a result, a limited number of public datasets are currently available for reflecting realistic operating conditions, which is insufficient to support robust, reproducible evaluation processes and the training of fine-grained ABAC models. This paper presents a contextual mapping method (CM-ABAC) for transforming Intrusion Detection Systems (IDS) cybersecurity datasets into access event representations suitable for ABAC assessment. The implementation of CM-ABAC creates datasets comprising access request events defined by contextual information such as the role, resource, location, time, and action attributes, plus a reference label indicating an expected decision (accept/reject). To evaluate reproducibility, three representative IDS datasets were transformed into ABAC-compatible traces using CM-ABAC. A transformation quality and scalability evaluation was conducted, followed by a case study on policy extraction, dynamic performance benchmarking, and a comparative analysis with a state-of-the-art synthetic data generator. The results show that the transformation preserves operational semantics such as network location, interaction type, and behavioral intent, features that are typically absent from synthetic ABAC generators. This demonstrates that CM-ABAC enables reproducible ABAC experimentation using the resulting datasets, such as policy-usage analysis, contextual pattern discovery, comparative studies of authorization behavior, and architectural stress testing.
Keywords:
Attribute-based access control
Intrusion-detection systems
Access log generation
Data mapping
Cybersecurity datasets

Journal

C
COMPUTERS & SECURITY
IF:
5.4
Papers:
164
Citations:
0

Organization

C
cinvestav tamaulipas
Scholars:
10
Papers: 5
Citations: 0
C
cinvestav guadalajara
Scholars:
3
Papers: 2
Citations: 0
Cited Papers

Cited Papers

Citing Papers

Citing Papers