{"id":{"repo_id":"london-metro","oai_identifier":"oai:repository.londonmet.ac.uk:10666"},"canonical_url":"https://search.dev.ndltd.org/etd/london-metro/oai:repository.londonmet.ac.uk:10666","repository":{"repo_id":"london-metro","name":"London Metropolitan University","base_url":"https://repository.londonmet.ac.uk/cgi/oai2"},"display":{"title":"Framework for analysis of the logical vulnerability of authentication procedures","abstract":"While AI has made strides in knowledge and action modelling, challenges remain in addressing security concerns like logical vulnerabilities in authentication policies. These vulnerabilities arise from flawed or missing authentication mechanisms, making operations unintentionally accessible. Our objective is to model the domain and find such vulnerabilities. Our approach is based on a novel three-level framework, specifically focusing on identifying logical vulnerabilities in authentication policies. Each level is built on top of the previous one. The first is the ontological level, where we model the static domain using Description Logics serialised as Ontology Web Language, providing a foundational representation of classes and relationships. The second is the logical level, where action rules, capturing system dynamics, are formalised using Horn Clause and First-Order Logic, serialised as Semantic Web Rule Language. We address the frame problem through efficient parameter utilisation as a side effect. The third is the analytical level, where we transform action rules into a policies graph to validate and visualise them and transform assertions into an instance graph to visualise the specific instance of the world to facilitate the analysis. We leverage the reasoner and control constant in an algorithmic approach, which detects vulnerabilities in the policies by finding vulnerable situations. We demonstrate the framework’s effectiveness and practicality through experimental evaluation with two real-world applications. Results highlight its scalability, explainability, and accuracy in detecting vulnerabilities, showcasing its potential to enhance security policy analysis.","abstract_html":"While AI has made strides in knowledge and action modelling, challenges remain in addressing security concerns like logical vulnerabilities in authentication policies. These vulnerabilities arise from flawed or missing authentication mechanisms, making operations unintentionally accessible. Our objective is to model the domain and find such vulnerabilities. Our approach is based on a novel three-level framework, specifically focusing on identifying logical vulnerabilities in authentication policies. Each level is built on top of the previous one. The first is the ontological level, where we model the static domain using Description Logics serialised as Ontology Web Language, providing a foundational representation of classes and relationships. The second is the logical level, where action rules, capturing system dynamics, are formalised using Horn Clause and First-Order Logic, serialised as Semantic Web Rule Language. We address the frame problem through efficient parameter utilisation as a side effect. The third is the analytical level, where we transform action rules into a policies graph to validate and visualise them and transform assertions into an instance graph to visualise the specific instance of the world to facilitate the analysis. We leverage the reasoner and control constant in an algorithmic approach, which detects vulnerabilities in the policies by finding vulnerable situations. We demonstrate the framework’s effectiveness and practicality through experimental evaluation with two real-world applications. Results highlight its scalability, explainability, and accuracy in detecting vulnerabilities, showcasing its potential to enhance security policy analysis.","abstract_has_math":false,"creators":["Bataityte, Karolina"],"institution":"London Metropolitan University","degree_name":"phd","degree_level":"doctoral","degree_discipline":null,"degree_department":null,"school":null,"contributors":[],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2025,"date_issued":"2025-08","date_published":"2025-08","updated_at":"2026-07-24T02:54:47Z","subjects":["000 Computer science, information & general works"],"languages":[],"rights":[],"rights_urls":[],"identifier_entries":[{"key":"dc:identifier.grantnumber","label":"Dc Identifier Grantnumber","values":["N/A"],"render_values":[{"text":"N/A","href":null,"code":true}]}]},"links":{"outbound_url":null,"outbound_label":null,"outbound_source":null},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.sponsor","label":"Sponsor","values":["London Metropolitan University"]},{"key":"dc:creator","label":"Author","values":["Bataityte, Karolina"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2025-08"]},{"key":"dc:date.issued","label":"Date","values":["2025-08"]},{"key":"dc:publisher.department","label":"Dc Publisher Department","values":["School of Computing and Digital Media (SCDM)","School of Computing and Digital Media"]},{"key":"dc:publisher.institution","label":"Dc Publisher Institution","values":["London Metropolitan University"]},{"key":"dc:relation.isreferencedby","label":"Dc Relation Isreferencedby","values":["https://repository.londonmet.ac.uk/10666/"]},{"key":"dc:type","label":"Dc Type","values":["Thesis"]},{"key":"dc:type.qualificationlevel","label":"Dc Type Qualificationlevel","values":["doctoral"]},{"key":"dc:type.qualificationname","label":"Dc Type Qualificationname","values":["phd"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["000 Computer science, information & general works"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.grantnumber","label":"Dc Identifier Grantnumber","values":["N/A"]},{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://repository.londonmet.ac.uk/10666/1/14013551_Karolina%20Bataityte.pdf"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["While AI has made strides in knowledge and action modelling, challenges remain in addressing security concerns like logical vulnerabilities in authentication policies. These vulnerabilities arise from flawed or missing authentication mechanisms, making operations unintentionally accessible. Our objective is to model the domain and find such vulnerabilities. Our approach is based on a novel three-level framework, specifically focusing on identifying logical vulnerabilities in authentication policies. Each level is built on top of the previous one. The first is the ontological level, where we model the static domain using Description Logics serialised as Ontology Web Language, providing a foundational representation of classes and relationships. The second is the logical level, where action rules, capturing system dynamics, are formalised using Horn Clause and First-Order Logic, serialised as Semantic Web Rule Language. We address the frame problem through efficient parameter utilisation as a side effect. The third is the analytical level, where we transform action rules into a policies graph to validate and visualise them and transform assertions into an instance graph to visualise the specific instance of the world to facilitate the analysis. We leverage the reasoner and control constant in an algorithmic approach, which detects vulnerabilities in the policies by finding vulnerable situations. We demonstrate the framework’s effectiveness and practicality through experimental evaluation with two real-world applications. Results highlight its scalability, explainability, and accuracy in detecting vulnerabilities, showcasing its potential to enhance security policy analysis."]},{"key":"dc:format","label":"Dc Format","values":["text"]},{"key":"dc:title","label":"Title","values":["Framework for analysis of the logical vulnerability of authentication procedures"]}]}],"canonical_facts":{"dc:contributor.sponsor":["London Metropolitan University"],"dc:creator":["Bataityte, Karolina"],"dc:date":["2025-08"],"dc:date.issued":["2025-08"],"dc:description.abstract":["While AI has made strides in knowledge and action modelling, challenges remain in addressing security concerns like logical vulnerabilities in authentication policies. These vulnerabilities arise from flawed or missing authentication mechanisms, making operations unintentionally accessible. Our objective is to model the domain and find such vulnerabilities. Our approach is based on a novel three-level framework, specifically focusing on identifying logical vulnerabilities in authentication policies. Each level is built on top of the previous one. The first is the ontological level, where we model the static domain using Description Logics serialised as Ontology Web Language, providing a foundational representation of classes and relationships. The second is the logical level, where action rules, capturing system dynamics, are formalised using Horn Clause and First-Order Logic, serialised as Semantic Web Rule Language. We address the frame problem through efficient parameter utilisation as a side effect. The third is the analytical level, where we transform action rules into a policies graph to validate and visualise them and transform assertions into an instance graph to visualise the specific instance of the world to facilitate the analysis. We leverage the reasoner and control constant in an algorithmic approach, which detects vulnerabilities in the policies by finding vulnerable situations. We demonstrate the framework’s effectiveness and practicality through experimental evaluation with two real-world applications. Results highlight its scalability, explainability, and accuracy in detecting vulnerabilities, showcasing its potential to enhance security policy analysis."],"dc:format":["text"],"dc:identifier.grantnumber":["N/A"],"dc:identifier.uri":["https://repository.londonmet.ac.uk/10666/1/14013551_Karolina%20Bataityte.pdf"],"dc:publisher.department":["School of Computing and Digital Media (SCDM)","School of Computing and Digital Media"],"dc:publisher.institution":["London Metropolitan University"],"dc:relation.isreferencedby":["https://repository.londonmet.ac.uk/10666/"],"dc:subject":["000 Computer science, information & general works"],"dc:title":["Framework for analysis of the logical vulnerability of authentication procedures"],"dc:type":["Thesis"],"dc:type.qualificationlevel":["doctoral"],"dc:type.qualificationname":["phd"]},"updated_at":"2026-07-24T02:54:47Z"}