首页> 外文会议>2011 IEEE Ninth International Conference on Dependable, Autonomic and Secure Computing >Self-Adaptive Authorization Framework for Policy Based RBAC/ABAC Models
【24h】

Self-Adaptive Authorization Framework for Policy Based RBAC/ABAC Models

机译:基于策略的RBAC / ABAC模型的自适应授权框架

获取原文

摘要

Authorization systems are an integral part of any network where resources need to be protected. They act as the gateway for providing (or denying) subjects (users) access to resources. As networks expand and organisations start to federate access to their resources, authorization infrastructures become increasingly difficult to manage. In this paper, we explore the potential of self-adaptive authorization as a means to automate the management of the access control configuration. We propose a Self-Adaptive Authorization Framework (SAAF) that is capable of managing any policy based distributed RBAC/ABAC authorization infrastructure. SAAF relies on a feedback control loop to monitor decisions (by policy decision points) of a target authorization infrastructure. These decisions are analysed to form a view of the subject's behaviour to decide whether to adapt the target authorization infrastructure. Adaptations are made in order to either endorse or restrict the identified behaviour, e.g. by loosening or tightening the current authorization policy. We demonstrate in terms of representative scenarios SAAF's ability for detecting abnormal behaviour, such as, misuse of access to system resources, proposing solutions that either prevent/endorse such behaviour, applying a cost function to each of these solutions, and executing the adaptive changes against a target authorization infrastructure.
机译:授权系统是需要保护资源的任何网络的组成部分。它们充当提供(或拒绝)主题(用户)对资源的访问的网关。随着网络的扩展和组织开始联合访问其资源,授权基础结构变得越来越难以管理。在本文中,我们探索了自适应授权作为一种自动进行访问控制配置管理的方法的潜力。我们提出了一种自适应授权框架(SAAF),该框架能够管理任何基于策略的分布式RBAC / ABAC授权基础结构。 SAAF依赖于反馈控制回路来监视目标授权基础结构的决策(通过策略决策点)。分析这些决策以形成对象行为的观点,以决定是否适应目标授权基础结构。为了适应或限制所识别的行为,例如进行修改。通过放宽或收紧当前的授权政策。我们通过代表性场景证明SAAF能够检测异常行为,例如滥用系统资源的访问权限,提出可防止/认可此类行为的解决方案,将成本函数应用于这些解决方案中的每一个,以及针对这些行为执行适应性更改,目标授权基础结构。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号