Cost-Effective Enforcement of Access and Usage Control Policies Under Uncertainties

被引:2
|
作者
Krautsevich, Leanid [1 ]
Lazouski, Aliaksandr [2 ]
Martinelli, Fabio [2 ]
Yautsiukhin, Artsiom [2 ]
机构
[1] Univ Pisa, Dept Comp Sci, I-56127 Pisa, Italy
[2] CNR, Ist Informat & Telemat, I-56124 Pisa, Italy
来源
IEEE SYSTEMS JOURNAL | 2013年 / 7卷 / 02期
基金
欧盟第七框架计划;
关键词
Costs; freshness; Markov chains; mutable attribute; policy enforcement; usage control; MANAGEMENT; SECURITY;
D O I
10.1109/JSYST.2012.2221911
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In usage control, access decisions rely on mutable attributes. A reference monitor should reevaluate security policies each time attributes change their values. Identifying all attribute changes in a timely manner is a challenging issue, especially if the attribute provider and the reference monitor reside in different security domains. Some attribute changes might be missed, corrupted, and delayed. As a result, the reference monitor may erroneously grant access to malicious users and forbid it for eligible ones. This paper proposes a set of policy enforcement models that help mitigate the uncertainties associated with mutable attributes. In our model, the reference monitor, as usual, evaluates logical predicates over attributes and, additionally, makes some estimates on how much observed attribute values differ from reality. The final access decision takes into account both factors. We assign costs for granting and revoking access to legitimate and malicious users and compare the proposed policy enforcement models in terms of cost efficiency.
引用
收藏
页码:223 / 235
页数:13
相关论文
共 50 条
  • [1] Identifying cost-effective dynamic policies to control epidemics
    Yaesoubi, Reza
    Cohen, Ted
    STATISTICS IN MEDICINE, 2016, 35 (28) : 5189 - 5209
  • [2] Concurrent enforcement of usage control policies
    Janicke, Helge
    Cau, Antonio
    Siewe, Francois
    Zedan, Hussein
    2008 IEEE WORKSHOP ON POLICIES FOR DISTRIBUTED SYSTEMS AND NETWORKS, PROCEEDINGS, 2008, : 111 - 118
  • [3] COST-EFFECTIVE ENFORCEMENT OF ENVIRONMENTAL STANDARDS
    DOWNING, PB
    WATSON, WB
    JOURNAL OF THE AIR POLLUTION CONTROL ASSOCIATION, 1975, 25 (07): : 705 - 710
  • [4] Verification and enforcement of access control policies
    Antonio Cau
    Helge Janicke
    Ben Moszkowski
    Formal Methods in System Design, 2013, 43 : 450 - 492
  • [5] Verification and enforcement of access control policies
    Cau, Antonio
    Janicke, Helge
    Moszkowski, Ben
    FORMAL METHODS IN SYSTEM DESIGN, 2013, 43 (03) : 450 - 492
  • [6] Cost-Effective and Anonymous Access Control for Wireless Body Area Networks
    Li, Fagen
    Han, Yanan
    Jin, Chunhua
    IEEE SYSTEMS JOURNAL, 2018, 12 (01): : 747 - 758
  • [7] Are fruit and vegetable voucher policies cost-effective?
    de Mouzon, O.
    Requillart, V.
    Soler, L. -G.
    Dallongeville, J.
    Dauchet, L.
    EUROPEAN REVIEW OF AGRICULTURAL ECONOMICS, 2012, 39 (05) : 771 - 795
  • [8] Cost-effective policies to reduce vehicle emissions
    Fullerton, D
    Gan, L
    AMERICAN ECONOMIC REVIEW, 2005, 95 (02): : 300 - 304
  • [9] NDE based cost-effective detection of obtrusive and coincident defects in pipelines under uncertainties
    Mukherjee, Subrata
    Huang, Xuhui
    Udpa, Lalita
    Deng, Yiming
    2019 PROGNOSTICS AND SYSTEM HEALTH MANAGEMENT CONFERENCE (PHM-PARIS), 2019, : 297 - 302
  • [10] A cost-effective ubiquitous wireless access network
    Nakayama, Masayoshi
    Yoshino, Shuichi
    Shimizu, Masashi
    NTT Technical Review, 2004, 2 (01): : 55 - 63