cs.CROct 5, 2026

Evaluating Behavioral Context for Interpretable IAM Policy Risk Scoring in Cloud Environments

Authors: Yassin Elsharkawy

Organizations: Dept. of Computers and Artificial Intelligence Capital University Cairo, Egypt

Abstract

IAM policy analysis typically emphasizes the authorization capabilities encoded in a policy, but security analyst review priority may also depend on the behavioral and environmental context surrounding a policy event. This paper evaluates whether contextual information provides measurable incremental value for interpretable IAM policy risk prioritization beyond policy and effective-authorization information. AWS is used as the experimental cloud provider because its IAM and audit-telemetry ecosystem enables controlled evaluation using AWS IAM Context Bench, a benchmark containing 534 real AWS experimental observations across policy, environment, and behavioral scenarios, including matched cases where policy and environment remain fixed while behavioral context changes. Three Explainable Boosting Machine models are evaluated under the same leakage-controlled grouped cross-validation protocol: a policy-centric baseline, a policy-plus-environment model, and a full-context model incorporating CloudTrail telemetry. The full-context model substantially reduces analyst-priority prediction error relative to the policy-centric baseline and closely tracks the reference priority ordering. In matched same-policy context pairs, the policy-centric model remains invariant, whereas the full-context model separates benign and suspicious behavioral conditions with high directional accuracy. The results also show improved concentration of high-priority cases at the top of simulated analyst review queues. These findings indicate that behavioral and environmental context can provide useful incremental information for analyst-oriented IAM risk prioritization while preserving an interpretable additive model structure. The formulation is applicable beyond AWS conceptually, although cross-provider validation remains future work.

Figures & tables

Explore similar work

CardsList
  1. AI Native Asset Intelligence

    May 9, 2026Gal Engelberg, Leon Goldberg, Konstantin Koutsyi +3

  2. Contextualization of Third-Party Cloud Security Findings

    Oct 6, 2026Leon Goldberg, Gal EngelbergSecurity EvaluationSeverity