Authorization-Aware Detection of OAuth Token Abuse: A Taxonomy and Behavioral Modeling Approach

Main Article Content

Ankush Banduni

Abstract

OAuth 2․0 is the de facto standard protocol for implementing delegated authorization in cloud-native and Software-as-a-Service (SaaS) applications․ Moreover‚ while the bearer-token-based implementation of OAuth 2․0 is broadly interoperable and improves the user experience‚ it is vulnerable to situations in which compromised access and refresh tokens can be abused by an attacker without triggering detection by authentication mechanisms․ While existing identity-threat detection methods mainly focus on authentication events‚ they do not consider if the post-issuance tokens contribute to risky behavior․ Our work contributes to two areas․ First‚ we present a taxonomy of OAuth token abuse based on the token acquisition vector‚ token type‚ privilege scope‚ and operational abuse pattern․ We then present a behavior-aware framework leveraging OAuth telemetry to monitor the token lifecycle‚ identify temporal and contextual features‚ establish per-client behavioral baselines using EWMA‚ compute risk scores using z-score normalization‚ and ease real-time adaptive mitigation against risky token operational abuse patterns․ Based on simulated workloads for SaaS APIs‚ the analysis of behavioral anomalies resulting from geographic variance‚ fluctuation in API calls‚ and scope misuse is demonstrated to be feasible in a longitudinal manner․ The proposed system achieves a 94․2% detection rate at 3․1% false positive rate when the thresholds are effectively calibrated‚ outperforming the authentication-only baselines by over 18 percentage points․ It acts as a foundation for authorization-aware identity security in modern distributed enterprise architectures․

Article Details

Section
Articles