Aller au contenu principal
Accès ouvert déclaré 2026 article

Policy-Consistent Change Provenance for Legitimacy Validation of Enterprise Configuration Modifications

0Citations signalées — pas une note de qualité
1Institutions déclarées
1Pays d’affiliation déclarés

Résumé fourni par la source

Enterprise configuration changes are often governed through tickets, approved actors, and maintenance windows, yet these procedural signals do not guarantee that the realized modification remains within the semantic scope of what was approved. This paper formulates configuration legitimacy validation as the problem of distinguishing procedurally supported changes from semantically authorized changes. We introduce the Configuration Approval-Intent Language (CAIL), a bounded approval-intent model that represents approved target, field, operation, actor, temporal, semantic, and governance constraints. We then present Policy-Consistent Change Provenance (PCCP), a lightweight deterministic validator that combines artifact-level change evidence, provenance context, policy admissibility, and CAIL-based approval-intent consistency to classify configuration modifications as Authorized, Unauthorized, or DeceptivelyAuthorized. To support reproducible evaluation, we introduce ConfigLegit-Bench, a controlled benchmark artifact designed around approval-intent semantics, policy-distinct scenarios, semi-real artifacts, and diagnostic stress tests. Across ten benchmark-generation seeds, PCCP achieved the strongest global performance among deterministic validators, with $0.8885 \pm 0.0035$ accuracy, $0.8853 \pm 0.0038$ macro-F1, and $0.7992 \pm 0.0076$ DeceptivelyAuthorized F1 on the main split. Learning-based full-structured baselines achieved higher deceptive-class sensitivity in some settings, indicating that PCCP should not be interpreted as the strongest detector under every metric. Its contribution is instead deterministic, interpretable, and policy-consistent legitimacy validation under explicit approval-intent semantics. Policy-distinct and semi-real evaluations further support the value of policy-conditioned and approval-intent-aware validation. However, diagnostic stress tests show that PCCP generalizes conservatively outside the modeled taxonomy. In particular, the unseen-variant stress test shows that PCCP alone has low recall for deceptive variants outside the predefined taxonomy; therefore, PCCP should be interpreted as a validator for modeled approval-intent mismatch types rather than as a standalone detector for arbitrary novel deceptive authorization. The contribution is therefore not unrestricted deceptive-authorization detection, but a deterministic, interpretable, and benchmark-grounded framework for studying policy-consistent configuration legitimacy validation.

Ce résumé expose les affirmations des auteurs. BNTIC ne l’interprète pas comme une validation indépendante des résultats.

Contrôle bibliographique ouvert

DOI retrouvé dans Crossref DOI retrouvé ; titre concordant.

Titre Crossref
Policy-Consistent Change Provenance for Legitimacy Validation of Enterprise Configuration Modifications
Date Crossref
01/01/2026
Éditeur
Institute of Electrical and Electronics Engineers (IEEE)
Type
journal-article

Ce recoupement confirme des métadonnées liées au DOI. Il ne confirme ni la méthode ni les conclusions de l’étude et ne compte pas comme une seconde source scientifique indépendante.

Institutions déclarées

Une affiliation ne permet pas de déduire la nationalité d’un auteur.

Sujets associés

Business Process Modeling and AnalysisInformation Technology Governance and StrategyProduct Development and Customization

BNTIC News n’est pas le producteur de ces données. Recherche à la demande dans Crossref et Europe PMC, sans clé ; OpenAlex reste optionnel. Aucun service payant requis, aucune réponse conservée. Sources et limites.