...
首页> 外文期刊>International journal of knowledge and learning >Log content extraction engine based on ontology for the purpose of a posteriori access control
【24h】

Log content extraction engine based on ontology for the purpose of a posteriori access control

机译:基于后验访问控制的基于本体的日志内容提取引擎

获取原文
获取原文并翻译 | 示例
           

摘要

In some complex information systems, users do not undergo untimely access controls. Generally, whenever they perform an action, this action is logged by the target system. Based on these log files, a security control called a posteriori access control is made afterwards. The logged data can be recorded in different formats (Syslog, W3C extend log, specific domain log standard like IHE-ATNA, etc.). An a posteriori security control framework requires a log filtering engine which extracts useful information regardless of the log format used. In this paper, we define and enforce this extraction function by building an ontology model of logs. This logs ontology is queried to check the compliance of actions performed by the users of the considered system with its access control policy (violations, anomalies, fulfilments, etc.). We show how the a posteriori security controls are made effective and how security decisions are made easier based on this extraction function.
机译:在某些复杂的信息系统中,用户不会受到不及时的访问控制。通常,每当他们执行某个操作时,该操作就会被目标系统记录下来。根据这些日志文件,随后进行称为后验访问控制的安全控制。记录的数据可以以不同的格式记录(Syslog,W3C扩展日志,特定的域日志标准,例如IHE-ATNA等)。后验安全控制框架要求使用日志过滤引擎来提取有用的信息,而与所使用的日志格式无关。在本文中,我们通过构建日志的本体模型来定义和执行此提取功能。查询此日志本体以检查所考虑系统的用户执行的操作与其访问控制策略(违规,异常,实现等)的一致性。我们将展示如何基于此提取功能有效地实现后验安全控制以及如何使安全决策变得更加容易。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号