首页> 外文会议>IFIP Conference on E-Commerce, E-Business, E-Government >Extending RBAC for Large Enterprisesand Its Quantitative Risk Evaluation
【24h】

Extending RBAC for Large Enterprisesand Its Quantitative Risk Evaluation

机译:为大型企业扩展RBAC,其定量风险评估

获取原文

摘要

Systems and security products based on the RBAC modelhave been widely introduced to enterprises. Especially, the demands onenforcement of enterprise-level security policies and total identity man-agement are rapidly growing. The RBAC model needs to be extendedto deal with various circumstances of large enterprises, such as ge-ographical distribution and heterogeneous environments includingphysical access control. In this paper, we introduce a new RBAC model, suitable for single sign-on systems. This model optimizesevaluation of rule-based RBAC so that total operation costs and pro-ductivity can be improved. Furthermore, to select most cost-effective RBAC extensions for en-terprise-wide requirements, we propose a quantitative risk evaluationmethod based on fault trees. We construct fault trees having securityviolation and productivity loss as top events, and RBAC standard func-tions and security incidents as basic events. Probabilities of the topevents are computed for given RBAC models and operation environ-ments. We apply this method to a real enterprise system using theabove RBAC extension and the proposed model realizes more safetyand productivity over the base model.
机译:基于RBAC型号的系统和安全产品已被广泛引入企业。特别是,对企业级安全政策的要求持续削减和全身识别人类绩效迅速增长。 RBAC模型需要扩展到大型企业的各种情况,例如Ge-ographical分布和异构环境包括本体访问控制。在本文中,我们介绍了一个新的RBAC模型,适用于单一登录系统。该模型优化基于规则的RBAC,因此可以提高总运营成本和促进性。此外,选择最具成本效益的RBAC延伸,我们提出了基于故障树的定量风险评估方法。我们构建具有安全性和生产力损失的故障树作为最佳事件,以及RBAC标准函数和安全事件作为基本事件。针对给定RBAC模型和操作环境计算的顶端子的概率。我们将此方法应用于使用TheaBove RBAC扩展的真实企业系统,并且所提出的模型实现了更多的安全性和基础模型的生产率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号