...
首页> 外文期刊>International Journal of Computer Network and Information Security >Validation of an Adaptive Risk-based Access Control Model for the Internet of Things
【24h】

Validation of an Adaptive Risk-based Access Control Model for the Internet of Things

机译:物联网的基于风险的自适应访问控制模型的验证

获取原文
           

摘要

The Internet of Things (IoT) has spread into multiple dimensions that incorporate different physical and virtual things. These things are connected together using different communication technologies to provide unlimited services. These services help not only to improve the quality of our daily lives, but also to provide a communication platform for increasing object collaboration and information sharing. Like all new technologies, the IoT has many security challenges that stand as a barrier to the successful implementation of IoT applications. These challenges are more complicated due to the dynamic and heterogeneous nature of IoT systems. However, authentication and access control models can be used to address the security issue in the IoT. To increase information sharing and availability, the IoT requires a dynamic access control model that takes not only access policies but also real-time contextual information into account when making access decisions. One of the dynamic features is the security risk. This paper proposes an Adaptive Risk-Based Access Control (AdRBAC) model for the IoT and discusses its validation using expert reviews. The proposed AdRBAC model conducts a risk analysis to estimate the security risk value associated with each access request when making an access decision. This model has four inputs/risk factors: user context, resource sensitivity, action severity and risk history. These risk factors are used to estimate a risk value associated with the access request to make the access decision. To provide the adaptive features, smart contracts will be used to monitor the user behaviour during access sessions to detect any malicious actions from the granted users. To validate and refine the proposed model, twenty IoT security experts from inside and outside the UK were interviewed. The experts have suggested valuable information that will help to specify the appropriate risk factors and risk estimation technique for implantation of the AdRBAC model.
机译:物联网(IoT)已扩展到多个维度,其中融合了不同的物理和虚拟事物。这些事物使用不同的通信技术连接在一起以提供无限的服务。这些服务不仅有助于改善我们的日常生活质量,而且还为增加对象协作和信息共享提供了一个交流平台。与所有新技术一样,物联网也面临许多安全挑战,成为成功实施物联网应用程序的障碍。由于物联网系统的动态性和异构性,这些挑战更加复杂。但是,身份验证和访问控制模型可用于解决物联网中的安全问题。为了增加信息共享和可用性,物联网需要动态访问控制模型,该模型在制定访问决策时不仅要考虑访问策略,还要考虑实时上下文信息。动态特性之一是安全风险。本文提出了一种用于物联网的自适应基于风险的访问控制(AdRBAC)模型,并使用专家评论讨论了其验证。提出的AdRBAC模型进行风险分析,以在做出访问决策时估算与每个访问请求相关的安全风险值。该模型具有四个输入/风险因素:用户上下文,资源敏感性,操作严重性和风险历史记录。这些风险因素用于估计与访问请求相关的风险值,以做出访问决策。为了提供自适应功能,智能合约将用于在访问会话期间监视用户行为,以检测来自授权用户的任何恶意行为。为了验证和完善建议的模型,采访了来自英国内外的20位物联网安全专家。专家们提出了有价值的信息,这些信息将有助于为AdRBAC模型的植入指定合适的风险因素和风险估计技术。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号