...
首页> 外文期刊>Future generation computer systems >TIRIAC: A trust-driven risk-aware access control framework for Grid environments
【24h】

TIRIAC: A trust-driven risk-aware access control framework for Grid environments

机译:TIRIAC:用于网格环境的信任驱动的风险感知访问控制框架

获取原文
获取原文并翻译 | 示例
           

摘要

The infrastructure provided by a Grid enables researchers to collaboratively solve various research problems through sharing their resources and establishing virtual organizations (VOs). However, the distributed and dynamic nature of a Grid VO is a challenge for access control systems. All users in a VO have responsibilities which correspond to their rights. While they should be able to make use of all VO resources, irresponsibility and permission misuse (insider attack) impose costs and losses on the affected resources. Hence, the history of users' behavior and the possibility of misuse need to be considered in the resource providers' risk management process. In this paper, we propose the TIRIAC framework for Grid access control. TIRIAC is the first trust-driven risk-aware access control framework which uses obligations to seamlessly monitor users and mitigate risks. In the TIRIAC framework, trust evaluation and risk management are added to the base Grid access control services. Thereafter, site administrators can explicitly specify users' responsibilities in form of obligations alongside access control rules. In addition, obligation-specific policies can be specified to mitigate risks according to their severity. We study the adoption of our framework by the European Grid Infrastructure (EGI), and demonstrate its superiority in comparison with the related work using multiple criteria. Moreover, we evaluate the performance of the framework and demonstrate its scalability in simulation experiments.
机译:网格提供的基础架构使研究人员可以通过共享资源和建立虚拟组织(VO)来共同解决各种研究问题。但是,Grid VO的分布式和动态性质对访问控制系统构成了挑战。 VO中的所有用户都有与其权利相对应的责任。尽管他们应该能够利用所有VO资源,但不负责任和滥用权限(内部攻击)会给受影响的资源带来成本和损失。因此,在资源提供者的风险管理过程中需要考虑用户的行为历史和滥用的可能性。在本文中,我们提出了用于网格访问控制的TIRIAC框架。 TIRIAC是第一个信任驱动的风险意识访问控制框架,该框架使用义务无缝监视用户并减轻风险。在TIRIAC框架中,将信任评估和风险管理添加到基本的Grid访问控制服务中。此后,站点管理员可以以义务的形式与访问控制规则一起明确指定用户的职责。此外,可以指定特定于义务的策略来根据风险的严重性减轻风险。我们研究了欧洲网格基础架构(EGI)对我们框架的采用,并证明了与使用多个标准的相关工作相比,它的优越性。此外,我们评估了框架的性能,并在仿真实验中证明了其可扩展性。

著录项

  • 来源
    《Future generation computer systems》 |2016年第2期|238-254|共17页
  • 作者单位

    Data and Network Security Laboratory, Department of Computer Engineering, Sharif University of Technology, Azadi Ave., Tehran, P.O. Box 11365-11155, Islamic Republic of Iran;

    Data and Network Security Laboratory, Department of Computer Engineering, Sharif University of Technology, Azadi Ave., Tehran, P.O. Box 11365-11155, Islamic Republic of Iran;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Trust; Risk; Obligations; Access control; Insider attack; Behavior uncertainty;

    机译:信任;风险;义务;访问控制;内部攻击;行为不确定性;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号