{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,26]],"date-time":"2026-05-26T05:02:45Z","timestamp":1779771765747,"version":"3.53.1"},"reference-count":42,"publisher":"MDPI AG","issue":"5","license":[{"start":{"date-parts":[[2026,5,21]],"date-time":"2026-05-21T00:00:00Z","timestamp":1779321600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Computers"],"abstract":"<jats:p>Role-Based Access Control (RBAC) is the de-facto mechanism for preserving Kubernetes and other cloud-native container platforms, however real deployments occasionally drift away from the principle of least privilege as clusters, teams, and services improve. This paper introduces an automated RBAC hardening framework that formulates least-privilege policy design as a limited optimization problem over RoleBindings and ClusterRoleBindings. The objective combines (i) a permission-risk score for namespaced and cluster-scoped actions with (ii) an operational complexity term that discourages overly large binding sets. Solid limitations encode functional requirements as well as practical security policies, which includes namespace allowlists, role scoping rules, administrative restrictions on cluster-wide bindings, binding budgets, and separation-of-duty requirements expressed by utilizing capability classes. To allow optimizer-agnostic search while protecting Kubernetes RBAC semantics, we analyze candidate policies by utilizing a unified penalty-based fitness function that compines risk, complexity, and constraint violations into a single scalar value. We utilized ten metaheuristic as a benchmark including baseline search paths on a Kubernetes-inspired instance and report feasibility and least-privilege quality metrics (precision, recall, F1, and over-privilege ratio) parallel to RB\/CRB counts and excess risk as a structural indicators. Outcomes present that feasibility is the prime challenge, and is restricted to a subset of optimizers reliably arrives to entirely feasible and compact arrangements within the exact budget, indicating the practicality of metaheuristic enhancement for systematic RBAC reduction in containerized cloud computing environments.<\/jats:p>","DOI":"10.3390\/computers15050326","type":"journal-article","created":{"date-parts":[[2026,5,21]],"date-time":"2026-05-21T13:53:24Z","timestamp":1779371604000},"page":"326","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Least-Privilege Role-Based Access Control Improvement for Cloud Container Security"],"prefix":"10.3390","volume":"15","author":[{"given":"Waleed K.","family":"Abdulraheem","sequence":"first","affiliation":[{"name":"Department of Intelligent Systems, Faculty of Artificial Intelligence, Al-Balqa Applied University, Al-Salt 19117, Jordan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Emad Mohammed","family":"Ibbini","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Faculty of Information Technology, Al al-Bayt University, Mafraq 25113, Jordan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hasan","family":"Kanaker","sequence":"additional","affiliation":[{"name":"Department of Information Security, Faculty of Information Technology, University of Petra, Amman 11942, Jordan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2152-4263","authenticated-orcid":false,"given":"Sami","family":"Smadi","sequence":"additional","affiliation":[{"name":"Department of Information Technology, Faculty of Information Technology and Computer Sciences, Yarmouk University, Irbid 21163, Jordan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Nader Abdel","family":"Karim","sequence":"additional","affiliation":[{"name":"Department of Intelligent Systems, Faculty of Artificial Intelligence, Al-Balqa Applied University, Al-Salt 19117, Jordan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9170-3291","authenticated-orcid":false,"given":"Hussam N.","family":"Fakhouri","sequence":"additional","affiliation":[{"name":"Department of Intelligent Systems, Faculty of Artificial Intelligence, Al-Balqa Applied University, Al-Salt 19117, Jordan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5088-2724","authenticated-orcid":false,"given":"Layla","family":"Albdour","sequence":"additional","affiliation":[{"name":"Cyber Security Department, Faculty of Science and Information Technology, Al-Zaytoonah University of Jordan, Amman 11733, Jordan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sandi","family":"Fakhouri","sequence":"additional","affiliation":[{"name":"Department of Computer Science, School of Information Technology, The University of Jordan, Amman 11942, Jordan"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2026,5,21]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"1278","DOI":"10.1109\/PROC.1975.9939","article-title":"The protection of information in computer systems","volume":"63","author":"Saltzer","year":"1975","journal-title":"Proc. IEEE"},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"237","DOI":"10.1016\/S0065-2458(08)60206-5","article-title":"Role-based access control","volume":"46","author":"Sandhu","year":"1998","journal-title":"Adv. Comput."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"224","DOI":"10.1145\/501978.501980","article-title":"Proposed NIST standard for role-based access control","volume":"4","author":"Ferraiolo","year":"2001","journal-title":"ACM Trans. Inf. Syst. Secur."},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Sanders, M.W., and Yue, C. (2018). Minimizing privilege assignment errors in cloud services. Proceedings of the Eighth ACM Conference on Data and Application Security and Privacy, Association for Computing Machinery.","DOI":"10.1145\/3176258.3176307"},{"key":"ref_5","unstructured":"Rastogi, V., Davidson, D., Carli, L.D., Jha, S., and McDaniel, P. (2016). Towards least privilege containers with cimplifier. arXiv."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Vaidya, J., Atluri, V., and Guo, Q. (2007). The role mining problem: Finding a minimal descriptive set of roles. Proceedings of the 12th ACM Symposium on Access Control Models and Technologies, Association for Computing Machinery.","DOI":"10.1145\/1266840.1266870"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Ene, A., Horne, W., Milosavljevic, N., Rao, P., Schreiber, R., and Tarjan, R.E. (2008). Fast exact and heuristic methods for role minimization problems. Proceedings of the 13th ACM Symposium on Access Control Models and Technologies, Association for Computing Machinery.","DOI":"10.1145\/1377836.1377838"},{"key":"ref_8","first-page":"2023","article-title":"Performance comparison of Hyper-V and KVM for cryptographic tasks in cloud computing","volume":"78","author":"Karim","year":"2024","journal-title":"Comput. Mater. Contin."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"763","DOI":"10.1145\/3689738","article-title":"Automatically reducing privilege for access control policies","volume":"8","author":"Ding","year":"2024","journal-title":"Proc. Acm Program. Lang."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"170:1","DOI":"10.1145\/3715001","article-title":"A container security survey: Exploits, attacks, and defenses","volume":"57","author":"Jarkas","year":"2025","journal-title":"ACM Comput. Surv."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Lu, H., Vaidya, J., and Atluri, V. (2008). Optimal boolean matrix decomposition: Application to role engineering. Proceedings of the 2008 IEEE 24th International Conference on Data Engineering, IEEE.","DOI":"10.1109\/ICDE.2008.4497438"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Molloy, I., Chen, H., Li, T., Wang, Q., Li, N., Bertino, E., Calo, S., and Lobo, J. (2008). Mining roles with semantic meanings. Proceedings of the 13th ACM Symposium on Access Control Models and Technologies, Association for Computing Machinery.","DOI":"10.1145\/1377836.1377840"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Xu, Z., and Stoller, S.D. (2012). Algorithms for mining meaningful roles. Proceedings of the 17th ACM Symposium on Access Control Models and Technologies, Association for Computing Machinery.","DOI":"10.1145\/2295136.2295146"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/2871148","article-title":"A survey of role mining","volume":"48","author":"Mitra","year":"2016","journal-title":"ACM Comput. Surv."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Vaidya, J., Atluri, V., Guo, Q., and Adam, N. (2008). Migrating to optimal RBAC with minimal perturbation. Proceedings of the 13th ACM Symposium on Access Control Models and Technologies, Association for Computing Machinery.","DOI":"10.1145\/1377836.1377839"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"1313","DOI":"10.1002\/cpe.1731","article-title":"Specifying and enforcing the principle of least privilege in role-based access control","volume":"23","author":"Ma","year":"2011","journal-title":"Concurr. Comput. Pract. Exp."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"63","DOI":"10.1007\/s10878-013-9633-9","article-title":"Handling least privilege problem and role mining in RBAC","volume":"30","author":"Huang","year":"2015","journal-title":"J. Comb. Optim."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Sanders, M.W., and Yue, C. (2019). Mining least privilege attribute based access control policies. Proceedings of the 35th Annual Computer Security Applications Conference, Association for Computing Machinery.","DOI":"10.1145\/3359789.3359805"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"140","DOI":"10.1016\/j.comcom.2020.12.006","article-title":"Role recommender-RBAC: Optimizing user-role assignments in RBAC","volume":"166","author":"Rao","year":"2021","journal-title":"Comput. Commun."},{"key":"ref_20","unstructured":"Tak, B., Isci, C., Duri, S., Bila, N., Nadgowda, S., and Doran, J. (2017). Understanding security implications of using containers in the cloud. Proceedings of the 2017 USENIX Annual Technical Conference (USENIX ATC 17), USENIX Association."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Torkura, K.A., Sukmana, M.I.H., Cheng, F., and Meinel, C. (2018). CAVAS: Neutralizing application and container security vulnerabilities in the cloud native era. Proceedings of the International Conference on Security and Privacy in Communication Systems, Springer.","DOI":"10.1007\/978-3-030-01701-9_26"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Sun, J., Wu, C., and Ye, J. (2020). Blockchain-based automated container cloud security enhancement system. Proceedings of the 2020 IEEE International Conference on Smart Cloud (SmartCloud), IEEE.","DOI":"10.1109\/SmartCloud49737.2020.00010"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Gao, X., Gu, Z., Kayaalp, M., Pendarakis, D., and Wang, H. (2017). Containerleaks: Emerging security threats of information leakages in container clouds. Proceedings of the 2017 47th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN), IEEE.","DOI":"10.1109\/DSN.2017.49"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"748","DOI":"10.1007\/s42979-023-02186-1","article-title":"Access security policy generation for containers as a cloud service","volume":"4","author":"Zhu","year":"2023","journal-title":"SN Comput. Sci."},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Li, Y., Hu, H., Liu, W., and Yang, X. (2023). An optimal active defensive security framework for the container-based cloud with deep reinforcement learning. Electronics, 12.","DOI":"10.3390\/electronics12071598"},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Yu, Z., Ye, L., Zhang, H., Zhan, D., Su, S., and Tian, Z. (2021). A container-oriented virtual-machine-introspection-based security monitor to secure containers in cloud computing. Proceedings of the International Conference on Artificial Intelligence and Security, Springer.","DOI":"10.1007\/978-3-030-78612-0_8"},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"174","DOI":"10.1109\/TDSC.2018.2879605","article-title":"A study on the security implications of information leakages in container clouds","volume":"18","author":"Gao","year":"2018","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"777","DOI":"10.1007\/s10586-025-05531-6","article-title":"Enhancing cloud native security: A knowledge graph approach for securing container runtimes","volume":"28","author":"Eldjou","year":"2025","journal-title":"Clust. Comput."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Nascimento, B., Santos, R., Henriques, J., Bernardo, M.V., and Caldeira, F. (2024). Availability, scalability, and security in the migration from container-based to cloud-native applications. Computers, 13.","DOI":"10.3390\/computers13080192"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Timofte, E.M., Balan, A.L., and Iftime, T. (2024). AI driven adaptive security mesh: Cloud container protection for dynamic threat landscapes. Proceedings of the 2024 International Conference on Development and Application Systems (DAS), IEEE.","DOI":"10.1109\/DAS61944.2024.10541148"},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"1942","DOI":"10.1109\/ICNN.1995.488968","article-title":"Particle swarm optimization","volume":"Volume 4","author":"Kennedy","year":"1995","journal-title":"Proceedings of ICNN\u201995-International Conference on Neural Networks"},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"46","DOI":"10.1016\/j.advengsoft.2013.12.007","article-title":"Grey wolf optimizer","volume":"69","author":"Mirjalili","year":"2014","journal-title":"Adv. Eng. Softw."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"51","DOI":"10.1016\/j.advengsoft.2016.01.008","article-title":"The whale optimization algorithm","volume":"95","author":"Mirjalili","year":"2016","journal-title":"Adv. Eng. Softw."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"120","DOI":"10.1016\/j.knosys.2015.12.022","article-title":"SCA: A sine cosine algorithm for solving optimization problems","volume":"96","author":"Mirjalili","year":"2016","journal-title":"Knowl.-Based Syst."},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Alkhatib, A., Shaheen, A., and Albustanji, R.N. (2024). A Comparative Analysis of Cloud Computing Services: AWS, Azure, and GCP, University of Bahrain.","DOI":"10.12785\/ijcds\/1571111846"},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Holland, J.H. (1992). Adaptation in Natural and Artificial Systems: An Introductory Analysis with Applications to Biology, Control, and Artificial Intelligence, MIT Press.","DOI":"10.7551\/mitpress\/1090.001.0001"},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Yang, X.-S. (2010). A new metaheuristic bat-inspired algorithm. Nature Inspired Cooperative Strategies for Optimization (NICSO 2010), Springer.","DOI":"10.1007\/978-3-642-12538-6_6"},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"671","DOI":"10.1126\/science.220.4598.671","article-title":"Optimization by simulated annealing","volume":"220","author":"Kirkpatrick","year":"1983","journal-title":"Science"},{"key":"ref_39","first-page":"281","article-title":"Random search for hyper-parameter optimization","volume":"13","author":"Bergstra","year":"2012","journal-title":"J. Mach. Learn. Res."},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"24691","DOI":"10.48084\/etasr.11575","article-title":"An efficient primary indexing method with sibling pointers for large-scale database systems","volume":"15","author":"Shaheen","year":"2025","journal-title":"Eng. Technol. Appl. Sci. Res."},{"key":"ref_41","doi-asserted-by":"crossref","unstructured":"Manning, C.D., Raghavan, P., and Sch\u00fctze, H. (2008). Introduction to Information Retrieval, Cambridge University Press.","DOI":"10.1017\/CBO9780511809071"},{"key":"ref_42","unstructured":"Powers, D.M.W. (2020). Evaluation: From precision, recall and F-measure to ROC, informedness, markedness and correlation. arXiv."}],"container-title":["Computers"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2073-431X\/15\/5\/326\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,26]],"date-time":"2026-05-26T04:14:13Z","timestamp":1779768853000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2073-431X\/15\/5\/326"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,21]]},"references-count":42,"journal-issue":{"issue":"5","published-online":{"date-parts":[[2026,5]]}},"alternative-id":["computers15050326"],"URL":"https:\/\/doi.org\/10.3390\/computers15050326","relation":{},"ISSN":["2073-431X"],"issn-type":[{"value":"2073-431X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,5,21]]}}}