curity expert interviews.
The results offer insights into the security strength
of the evaluated attributes, helping with creating se-
cure access policies. In terms of user attributes,
Password Authentication with high implementation
strength emerged as the most robust against compro-
mise, followed by Device Usage. Among device at-
tributes, Certificate Authentication exhibited the high-
est security strength, closely followed User Usage.
These findings enable a direct evaluation of the re-
sistance of ABAC policies to spoofing attacks. Based
on our case study results, policies incorporating the
aforementioned four attributes are less vulnerable to
such attacks. In TBAC systems, this information can
guide the weighting of attributes, suggesting assign-
ing the highest weights to these four attributes.
For future work, we aim to conduct more in-depth
analyses and interviews with security experts to over-
come the framework’s current limitation of relying
on single experts’ opinions when assessing attribute
feasibility levels. Our goal is to establish a general
and unbiased baseline for the feasibility levels of at-
tribute compromise, taking into account specific at-
tacker skills. Additionally, we plan to expand the risk
assessment to further attributes like passkeys.
