Back to results

London Metropolitan University

Framework for analysis of the logical vulnerability of authentication procedures

Abstract

dc:description.abstract

While AI has made strides in knowledge and action modelling, challenges remain in addressing security concerns like logical vulnerabilities in authentication policies. These vulnerabilities arise from flawed or missing authentication mechanisms, making operations unintentionally accessible. Our objective is to model the domain and find such vulnerabilities. Our approach is based on a novel three-level framework, specifically focusing on identifying logical vulnerabilities in authentication policies. Each level is built on top of the previous one. The first is the ontological level, where we model the static domain using Description Logics serialised as Ontology Web Language, providing a foundational representation of classes and relationships. The second is the logical level, where action rules, capturing system dynamics, are formalised using Horn Clause and First-Order Logic, serialised as Semantic Web Rule Language. We address the frame problem through efficient parameter utilisation as a side effect. The third is the analytical level, where we transform action rules into a policies graph to validate and visualise them and transform assertions into an instance graph to visualise the specific instance of the world to facilitate the analysis. We leverage the reasoner and control constant in an algorithmic approach, which detects vulnerabilities in the policies by finding vulnerable situations. We demonstrate the framework’s effectiveness and practicality through experimental evaluation with two real-world applications. Results highlight its scalability, explainability, and accuracy in detecting vulnerabilities, showcasing its potential to enhance security policy analysis.

Degree

thesis:*
Name dc:type.qualificationname
phd
Level dc:type.qualificationlevel
doctoral
Grantor dc:publisher.institution
London Metropolitan University
Year dc:date.issued
2025

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Bataityte, Karolina

Subjects

dc:subject × 1

Identifiers

dc:identifier.*
Dc Identifier Grantnumber
N/A
OAI identifier oai:identifier
oai:repository.londonmet.ac.uk:10666

Chain of custody

source
Harvested from
London Metropolitan University
Base URL
repository.londonmet.ac.uk/cgi/oai2
Last updated
2026-07-24
Source record
OAI-PMH GetRecord
citation

Bataityte, Karolina. Framework for analysis of the logical vulnerability of authentication procedures. doctoral thesis, London Metropolitan University, 2025.