OARAB: code and results for a benchmark and construction ablation of post-authentication resource abuse in OAuth 2.0
Description
Code and result files for the paper "OARAB: A Benchmark and Construction Ablation for Post-Authentication Resource Abuse in OAuth 2.0" (Mohd Adnan and Aasim Zafar, Aligarh Muslim University). OARAB generates labelled streams of authenticated resource access and evaluates whether a detector can separate abusive clients from legitimate ones once a bearer token has already been issued. Principals are human, machine-to-machine, power user, or abusive, and the abusive ones come at three difficulty tiers. Only behaviour carries the label; identity signatures and OAuth attributes are assigned independently of it. The archive contains the generator, the detector panel and evaluation harness, the loaders for the external corpora, the result files every number in the paper is read from, and the test suite that runs the validity guards. It also contains the audit trail the paper's abstract promises: a record of eight claims withdrawn during the revision, four of them results the submitted version reported, each raced to the artefact that refutes it. The generated snapshot and the behavioural profile bank are not included. The bank is fit to the ITI web-bot corpus, which is CC BY-NC-SA and which we do not redistribute in derived form. Generation is deterministic from one seeded stream, so the released snapshot rebuilds identically after fetching the corpus and fitting the bank; README.md gives the two commands. Until you do, the tests that generate from the bank will fail, which is expected rather than a defect. Requires Python 3.10 or newer.
Files
Institutions
- Aligarh Muslim UniversityUttar Pradesh, Aligarh