首页> 外文OA文献 >A web-based cooperative tool for risk management with adaptive security
【2h】

A web-based cooperative tool for risk management with adaptive security

机译:具有自适应安全性风险管理的基于网络的合作工具

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Risk management can benefit from Web-based tools fostering actions for treating risks in an environment, while having several individuals collaborating to face the endeavors related to risks. During the intervention, the security rules in place to preserve resources from unauthorized access, might need to be modified on the fly, e.g., increasing the privileges of risk managers or letting rescue teams view the exact position of the victims. Modifications should respect the overall security policies and avoid security conflicts. This paper presents a dynamic access control model for environmental risks involving physical resources. Data structures included in our Web application to represent both risk and security are given. To keep the dynamic security rules compliant with overall organization security objectives, we consider rules grouped in Access Control Domains so that changes do not create security conflicts during collaboration in risk management. Considering work environments as an example, risk and access control models are introduced. Security is built on the ABAC (Attribute Based Access Control) paradigm. A Risk Management System (RMS) is illustrated: it captures events, signals potential risks, and outputs strategies to prevent the risk. Dynamic authorization is included in the RMS to vary subjects' privileges on physical resources based on risk level, people position and so on. These concepts are implemented in a prototype Web application appearing as a Web Dashboard for risk management.
机译:风险管理可以从基于网络的工具中受益促进在环境中处理风险的行动,同时有几个人合作面对与风险相关的努力。在干预期间,可能需要在飞行中修改从未授权访问的安全规则以维护来自未经授权的访问的资源,例如,增加风险管理人员的特权或让救援团队查看受害者的确切位置。修改应尊重整体安全策略并避免安全冲突。本文介绍了涉及物理资源的环境风险的动态访问控制模型。给出了我们的Web应用程序中包含的数据结构以表示风险和安全性。为了保持符合整体组织安全目标的动态安全规则,我们考虑在访问控制域中分组的规则,以便在风险管理中协作期间更改不会创建安全冲突。考虑工作环境作为示例,介绍了风险和访问控制模型。安全性建立在ABAC(基于属性的访问控制)范例上。示出了风险管理系统(RMS):它捕获事件,信号潜在风险,并输出策略以防止风险。 RMS中包含动态授权,以基于风险级别,人们的位置等,在物理资源上有所不同的权限。这些概念在出现为风险管理的Web仪表板的原型Web应用程序中实现。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号