September 2026
Risk-Adaptive Authorization for Hybrid Cloud IAM
Catching an attacker who has a real password
A research paper from my eighth semester, with a demo you can click through. It asks two things about every request. Is this account acting normally, and how much power would this action hand it? Then it allows, questions, or refuses. The paper is unpublished.
Unpublished research · eighth semester
Most cloud break-ins involve no breaking. The key works, the request is signed, and the command is one that normal deploy tools run every day. The real question is not whether the request is allowed, but how much it hands over and whether this account usually asks for it.
- Role
- Co-author with Ashal Pandey and Famous Dhungana. I wrote up the design and built the browser demo.
- Organization
- BSc CSIT eighth semester · Madan Bhandari Memorial College, Tribhuvan University
Built with