RCBAC: A risk-aware content-based access control model for large-scale text data

被引:5
|
作者
Ma, Ke [1 ]
Yang, Geng [1 ,2 ]
Xiang, Yang [3 ]
机构
[1] Nanjing Univ Posts & Telecommun, Nanjing 210023, Peoples R China
[2] Jiangsu Key Lab Big Data Secur & Intelligent Proc, Nanjing 210023, Peoples R China
[3] Swinburne Univ Technol, Hawthorn, Vic 3122, Australia
基金
中国博士后科学基金; 中国国家自然科学基金;
关键词
Content-based access control; Risk-based access control; Big data; Unstructured data; Over-authorization; FRAMEWORK;
D O I
10.1016/j.jnca.2020.102733
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Unstructured data (mostly text data) have become a vital part in the era of big data. Hence, it has become increasingly difficult to identify the internal relations among data and describing the access control object during the design of access control (especially fine-grained access control) policies. Furthermore, in recent years, security incidents have frequently occurred due to the leakage of secrets by insiders, in both enterprises and government agencies around the world. Due to dynamic user behavior, it is difficult to determine "curious accesses" and grant authority based on traditional static access control models. Therefore, we need a dynamic access control model that is content-driven and can be used to find curious users in daily practice. This paper proposes a risk-aware content-based access control model (RCBAC) which can be used to solve over-authorization problems and can grant file-level authority to users. Based on the relevance of the data content and the duties of each user, RCBAC can quantify the risk of both the access behavior and the access history; accordingly, each user's access ability can be adjusted dynamically. The experimental results show that the RCBAC model can separate curious users from normal users and limit the access ability of curious users.
引用
收藏
页数:16
相关论文
共 50 条
  • [1] Content-Based Access Control: Use Data Content to Assist Access Control for Large-Scale Content-Centric Databases
    Zeng, Wenrong
    Yang, Yuhao
    Luo, Bo
    [J]. 2014 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2014, : 701 - 710
  • [2] RTBAC: A Risk-Aware Topic-Based Access Control Model for Text Data with Paragraph-Level Authorization
    Ma, Ke
    Yang, Geng
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2022, 2022
  • [3] A Content-based Indexing Scheme for Large-Scale Unstructured Data
    Zhu, Nan
    Lu, Yangdi
    He, Wenbo
    Yu, Hua
    [J]. 2017 IEEE THIRD INTERNATIONAL CONFERENCE ON MULTIMEDIA BIG DATA (BIGMM 2017), 2017, : 205 - 212
  • [4] A Framework for Risk-Aware Role Based Access Control
    Bijon, Khalid Zaman
    Krishnan, Ram
    Sandhu, Ravi
    [J]. 2013 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2013, : 462 - 469
  • [5] Risk-Aware Rapid Data Evacuation for Large-Scale Disasters in Optical Cloud Networks
    Li, Yongcheng
    Ferdousi, Sifat
    Colman-Meixner, Carlos
    Zhao, Yongli
    Tornatore, Massimo
    Shen, Gangxiang
    Mukherjee, Biswanath
    [J]. 2016 ASIA COMMUNICATIONS AND PHOTONICS CONFERENCE (ACP), 2016,
  • [6] Risk-Aware Model-Based Control
    Yu, Chen
    Rosendo, Andre
    [J]. FRONTIERS IN ROBOTICS AND AI, 2021, 8
  • [7] A Risk-aware Access Control Model for Biomedical Research Platforms
    Badji, Radja
    Dankar, Fida K.
    [J]. ICISSP: PROCEEDINGS OF THE 4TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2018, : 322 - 328
  • [8] Adaptive risk-aware access control model for Internet of Things
    Rath, Annanda Thavymony
    Colin, Jean-Noel
    [J]. 2017 INTERNATIONAL WORKSHOP ON SECURE INTERNET OF THINGS (SIOT 2017), 2017, : 40 - 49
  • [9] A content-based publish/subscribe framework for large-scale content delivery
    Diallo, Mohamed
    Sourlas, Vasilis
    Flegkas, Paris
    Fdida, Serge
    Tassiulas, Leandros
    [J]. COMPUTER NETWORKS, 2013, 57 (04) : 924 - 943
  • [10] On Interest Locality in Content-Based Routing for Large-scale MANETs
    Zhang, Yang
    Zhao, Jing
    Cao, Guohong
    Das, Chita R.
    [J]. 2009 IEEE 6TH INTERNATIONAL CONFERENCE ON MOBILE ADHOC AND SENSOR SYSTEMS (MASS 2009), 2009, : 339 - 348