A privacy-aware access control model for distributed network monitoring

被引:7
|
作者
Papagiannakopoulou, Eugenia I. [1 ]
Koukovini, Maria N. [1 ]
Lioudakis, Georgios V. [1 ]
Garcia-Alfaro, Joaquin [2 ]
Kaklamani, Dimitra I. [1 ]
Venieris, Iakovos S. [1 ]
Cuppens, Frederic [2 ]
Cuppens-Boulahia, Nora [2 ]
机构
[1] Natl Tech Univ Athens, Sch Elect & Comp Engn, Athens, Greece
[2] TELECOM Bretagne, Inst TELECOM, F-35576 Rennes, France
关键词
ANONYMIZATION; CRYPTOGRAPHY;
D O I
10.1016/j.compeleceng.2012.08.003
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we introduce a new access control model that aims at addressing the privacy implications surrounding network monitoring. In fact, despite its importance, network monitoring is natively leakage-prone and, moreover, this is exacerbated due to the complexity of the highly dynamic monitoring procedures and infrastructures, that may include multiple traffic observation points, distributed mitigation mechanisms and even interoperator cooperation. Conceived on the basis of data protection legislation, the proposed approach is grounded on a rich in expressiveness information model, that captures all the underlying monitoring concepts along with their associations. The model enables the specification of contextual authorisation policies and expressive separation and binding of duty constraints. Finally, two key innovations of our work consist in the ability to define access control rules at any level of abstraction and in enabling a verification procedure, which results in inherently privacy-aware workflows, thus fostering the realisation of the Privacy by Design vision. (C) 2012 Elsevier Ltd. All rights reserved.
引用
收藏
页码:2263 / 2281
页数:19
相关论文
共 50 条
  • [21] Assurance, Consent and Access Control for Privacy-Aware OIDC Deployments
    Sassetti, Gianluca
    Sharif, Amir
    Sciarretta, Giada
    Carbone, Roberto
    Ranise, Silvio
    DATA AND APPLICATIONS SECURITY AND PRIVACY XXXVII, DBSEC 2023, 2023, 13942 : 203 - 222
  • [22] Privacy-aware access control with trust management in web service
    Min Li
    Xiaoxun Sun
    Hua Wang
    Yanchun Zhang
    Ji Zhang
    World Wide Web, 2011, 14 : 407 - 430
  • [23] Efficient, Traceable and Privacy-Aware Data Access Control in Distributed Cloud-Based IoD Systems
    Ma, Zhuo
    Zhang, Jiawei
    IEEE ACCESS, 2023, 11 : 45206 - 45221
  • [24] Privacy-aware access control through negotiation in daily life service
    Park, Hyun-A
    Zhan, Justin
    Lee, Dong Hoon
    INTELLIGENCE AND SECURITY INFORMATICS, PROCEEDINGS, 2008, 5075 : 514 - +
  • [25] Privacy-aware multi-tenant access control for cloud workflow
    Wen Y.
    Liu J.
    Dou W.
    Chen A.
    Zhou M.
    Jisuanji Jicheng Zhizao Xitong/Computer Integrated Manufacturing Systems, CIMS, 2019, 25 (04): : 894 - 900
  • [26] Privacy-aware access control for video data in intelligent surveillance systems
    Vagts, Hauke
    Jakoby, Andreas
    MOBILE MULTIMEDIA/IMAGE PROCESSING, SECURITY, AND APPLICATIONS 2012, 2012, 8406
  • [27] Application of Privacy-aware Role-based Access Control Model in IHE-XDS
    Dauletbek, Daniya
    Yuan, Shi-Zhong
    4TH ANNUAL INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY AND APPLICATIONS (ITA 2017), 2017, 12
  • [28] A Category-Based Framework for Privacy-Aware Collaborative Access Control
    Obrezkov, Denis
    Sohr, Karsten
    Malaka, Rainer
    TRUST, PRIVACY AND SECURITY IN DIGITAL BUSINESS (TRUSTBUS 2021), 2021, 12927 : 126 - 139
  • [29] The Health Avatar Privacy-Aware Monitoring and Management
    Meridou, Despina T.
    Papadopoulou, Maria-Eleftheria Ch.
    Kasnesis, Panagiotis
    Patrikakis, Charalampos Z.
    Lamprinakos, Georgios
    Kapsalis, Andreas P.
    Venieris, Iakovos S.
    Kaklamani, Dimitra-Theodora I.
    IT PROFESSIONAL, 2015, 17 (05) : 20 - 27
  • [30] Multi-domain and Privacy-aware Role Based Access Control in eHealth
    Martino, Lorenzo D.
    Ni, Qun
    Lin, Dan
    Bertino, Elisa
    2008 2ND INTERNATIONAL CONFERENCE ON PERVASIVE COMPUTING TECHNOLOGIES FOR HEALTHCARE, 2008, : 123 - 126