Copyright © 2026 Authors retain the copyright of this article. This article is an open access article distributed under the Creative Commons Attribution License which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.
@article{203465,
author = {Shaista Afreen and Madhu Priya K and Hemalatha M},
title = {Privilege Entropy: An Information-Theoretic Metric for Measuring Cloud Account Overexposure in Multi-Cloud Environments},
journal = {International Journal of Innovative Research in Technology},
year = {2026},
volume = {12},
number = {12},
pages = {12526-12534},
issn = {2349-6002},
url = {https://ijirt.org/article?manuscript=203465},
abstract = {Cloud computing has fundamentally transformed enterprise infrastructure by enabling scalable, distributed, and dynamic resource provisioning. However, this flexibility introduces significant security risks, particularly due to excessive Identity and Access Management (IAM) privileges. Overprivileged accounts represent a major attack vector, enabling adversaries to perform privilege escalation, access sensitive resources, and compromise cloud environments. Traditional privilege risk assessment techniques rely on heuristic analysis, permission counts, or rule-based detection, which fail to capture the structural distribution and uncertainty of privilege assignments. This research introduces Privilege Entropy, a novel information-theoretic metric based on Shannon entropy for quantifying privilege exposure in cloud IAM systems. The proposed approach models permission assignments as probabilistic distributions and computes entropy to measure privilege diversity and uncertainty. Higher entropy values indicate broader privilege dispersion and increased attack surface exposure. The proposed framework supports multi-cloud environments, including Amazon Web Services (AWS), Google Cloud Platform (GCP), and Kubernetes (K8s), enabling platform independent privilege risk assessment. Experimental evaluation using real-world IAM policy datasets demonstrates that privilege entropy effectively identifies high-risk roles, particularly administrative and owner-level identities. Results show that the proposed entropy-based metric provides improved sensitivity and accuracy compared to traditional permission-count-based methods. The proposed approach offers a scalable, mathematically grounded, and forensic-ready solution for automated privilege risk analysis, cloud security auditing, and proactive threat detection in modern multi-cloud environments.},
keywords = {Cloud Security, IAM, Privilege Entropy, Information Theory, Multi-Cloud Security, Digital Forensics, Access Control, Shannon Entropy},
month = {May},
}
Submit your research paper and those of your network (friends, colleagues, or peers) through your IPN account, and receive 800 INR for each paper that gets published.
Join NowNational Conference on Sustainable Engineering and Management - 2024 Last Date: 15th March 2024
Submit inquiry