首页> 外文会议>The Fourth International Conference on Emerging Security Information Systems and Technologies >An Access Control Architecture for Context-Risk-Aware Access Control: Architectural Design and Performance Evaluation
【24h】

An Access Control Architecture for Context-Risk-Aware Access Control: Architectural Design and Performance Evaluation

机译:用于上下文风险感知访问控制的访问控制体系结构:体系结构设计和性能评估

获取原文

摘要

Risk assessment plays a significant role in Decision Support Systems (DSS). Recently, there have been efforts to exploit the potential of linking risk assessment to security provisioning to provide risk-aware security services. One of these efforts is the Context-Risk-Aware Access Control (CRAAC) model that links requestersȁ9; access privileges to the risk level in the underlying access environment in the context of Pervasive Computing (PerComp). The idea is to link an access control decision to an attribute value that reflects the aggregated assurance level in identifying a subject. This attribute value is named as Requesterȁ9;s Level of Assurance (RLoA) and is influenced by the requesterȁ9;s run-time contextual information. This paper proposes the CRAAC architecture along with its components to support this novel access control model. This architecture provides high level functional transparency, extensibility, and flexibility to cope with the PerComp dynamic nature. It describes the fundamental services provided by CRAAC, namely context monitoring, RLoA derivation, and RLoA-linked access control decision making. The paper also shows the results of some experiments, conducted on a CRAAC prototype, to evaluate the CRAAC performance (configured in the RLoA-only working mode). The experimental results show that the RLoA-only mode introduces only marginal access delays and is more resilient to Denial of Service (DoS) attacks compared to the traditional Role-Based Access Control (RBAC) model.
机译:风险评估在决策支持系统(DSS)中起着重要作用。最近,人们一直在努力开发将风险评估与安全性配置链接起来以提供风险感知安全性服务的潜力。这些工作之一是链接请求者9的上下文风险感知访问控制(CRAAC)模型。在普适计算(PerComp)的上下文中,将访问特权授予底层访问环境中的风险级别。这个想法是将访问控制决策与反映在确定主题时的汇总保证级别的属性值相关联。此属性值称为请求者9的保证水平(RLoA),并受请求者9的运行时上下文信息的影响。本文提出了CRAAC体系结构及其组件,以支持这种新颖的访问控制模型。该体系结构提供了高级功能透明性,可扩展性和灵活性,以应对PerComp的动态特性。它描述了CRAAC提供的基本服务,即上下文监视,RLoA派生和RLoA链接的访问控制决策。本文还显示了对CRAAC原型进行的一些实验结果,以评估CRAAC性能(在仅RLoA工作模式下配置)。实验结果表明,与传统的基于角色的访问控制(RBAC)模型相比,仅RLoA模式仅引入了少量访问延迟,并且更能抵抗拒绝服务(DoS)攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号