首页> 外文会议>Annual IEEE/IFIP International Conference on Dependable Systems and Networks >Evaluating Self-Adaptive Authorisation Infrastructures Through Gamification
【24h】

Evaluating Self-Adaptive Authorisation Infrastructures Through Gamification

机译:通过游戏化评估自适应授权基础结构

获取原文

摘要

Self-adaptive systems are able to modify their behaviour and/or structure in response to changes that occur to the system itself, its environment, or even its goals. In terms of authorisation infrastructures, self-adaptation has been shown to provide runtime capabilities for specifying and enforcing access control policies and subject access privileges, with a goal to mitigate insider threat. The evaluation of self-adaptive authorisation infrastructures, particularly, in the context of insider threats, is challenging because simulation of malicious behaviour can only demonstrate a fraction of the types of abuse that is representative of the real-world. In this paper, we present an innovative approach based on an ethical game of hacking, protected by an authorisation infrastructure. A key feature of the approach is the ability to observe user activity pre- and post-adaptation when evaluating runtime consequences of self-adaptation. Our live experiments captured a wide range of unpredictable changes, including malicious behaviour related to the exploitation of known vulnerabilities. As an outcome, we demonstrated the ability of our self-adaptive authorisation infrastructure to handle malicious behaviour given the existence of real and intelligent users, in addition to capturing how users responded to adaptation.
机译:自适应系统能够响应系统本身,其环境甚至其目标发生的更改来修改其行为和/或结构。在授权基础结构方面,自适应已显示提供运行时功能,用于指定和实施访问控制策略和主题访问特权,目的是减轻内部威胁。自适应授权基础结构的评估,尤其是在内部威胁的情况下,具有挑战性,因为对恶意行为的模拟只能证明代表真实世界的滥用类型的一小部分。在本文中,我们提出了一种基于道德操守游戏的创新方法,该方法受到授权基础结构的保护。该方法的主要功能是能够在评估自适应的运行时后果时观察自适应前后的用户活动。我们的现场实验捕获了各种各样的不可预测的变化,包括与利用已知漏洞有关的恶意行为。结果,我们展示了我们的自适应授权基础结构在存在真实和智能用户的情况下处理恶意行为的能力,此外还捕获了用户对适应的响应方式。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号