Evaluating Self-Adaptive Authorisation Infrastructures through Gamification

被引:1
|
作者
Bailey, Christopher [1 ]
de Lemos, Rogerio [1 ]
机构
[1] Univ Kent, Canterbury, Kent, England
关键词
self-adaptive systems; authorisation infrastructures; insider threats; gamification;
D O I
10.1109/DSN.2018.00058
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Self-adaptive systems are able to modify their behaviour and/or structure in response to changes that occur to the system itself, its environment, or even its goals. In terms of authorisation infrastructures, self-adaptation has been shown to provide runtime capabilities for specifying and enforcing access control policies and subject access privileges, with a goal to mitigate insider threat. The evaluation of self-adaptive authorisation infrastructures, particularly, in the context of insider threats, is challenging because simulation of malicious behaviour can only demonstrate a fraction of the types of abuse that is representative of the real-world. In this paper, we present an innovative approach based on an ethical game of hacking, protected by an authorisation infrastructure. A key feature of the approach is the ability to observe user activity pre- and post-adaptation when evaluating runtime consequences of self-adaptation. Our live experiments captured a wide range of unpredictable changes, including malicious behaviour related to the exploitation of known vulnerabilities. As an outcome, we demonstrated the ability of our self-adaptive authorisation infrastructure to handle malicious behaviour given the existence of real and intelligent users, in addition to capturing how users responded to adaptation.
引用
收藏
页码:502 / 513
页数:12
相关论文
共 50 条
  • [1] Malicious changeload for the resilience evaluation of self-adaptive authorisation infrastructures
    Bailey, Christopher
    Lemos, Rogerio de
    [J]. FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2020, 113 : 113 - 131
  • [2] Self-adaptive authorisation in OpenStack cloud platform
    Da Silva, Carlos Eduardo
    Diniz, Thomas
    Cacho, Nelio
    de Lemos, Rogerio
    [J]. JOURNAL OF INTERNET SERVICES AND APPLICATIONS, 2018, 9
  • [3] Self-adaptive federated authorization infrastructures
    Bailey, Christopher
    Chadwick, David W.
    de Lemos, Rogerio
    [J]. JOURNAL OF COMPUTER AND SYSTEM SCIENCES, 2014, 80 (05) : 935 - 952
  • [4] Evaluating the Effectiveness of the Rainbow Self-Adaptive System
    Cheng, Shang-Wen
    Garlan, David
    Schmerl, Bradley
    [J]. 2009 ICSE WORKSHOP ON SOFTWARE ENGINEERING FOR ADAPTIVE AND SELF-MANAGING SYSTEMS, 2009, : 132 - 141
  • [5] Research on Self-adaptive Algorithm in Self-adaptive Web System
    Cao, CaiFeng
    Luo, YaoZu
    Gong, Jing
    [J]. PROCEEDINGS OF THE 2015 INTERNATIONAL CONFERENCE ON INTELLIGENT SYSTEMS RESEARCH AND MECHATRONICS ENGINEERING, 2015, 121 : 25 - 28
  • [6] On Evaluating Self-Adaptive and Self-Healing Systems using Chaos Engineering
    Naqvi, Moeen Ali
    Malik, Sehrish
    Astekin, Merve
    Moonen, Leon
    [J]. 2022 IEEE INTERNATIONAL CONFERENCE ON AUTONOMIC COMPUTING AND SELF-ORGANIZING SYSTEMS (ACSOS 2022), 2022, : 1 - 10
  • [7] Self-adaptive and self-healing message passing strategies for process-oriented integration infrastructures
    Caseau, Y
    [J]. 11TH IEEE INTERNATIONAL CONFERENCE AND WORKSHOP ON THE ENGINEERING OF COMPUTER-BASED SYSTEMS, PROCEEDINGS, 2004, : 506 - 512
  • [8] Optimizing network measurements through self-adaptive sampling
    Silva, Joao Marco C.
    Lima, Solange Rito
    [J]. 2012 IEEE 14TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING AND COMMUNICATIONS & 2012 IEEE 9TH INTERNATIONAL CONFERENCE ON EMBEDDED SOFTWARE AND SYSTEMS (HPCC-ICESS), 2012, : 794 - 801
  • [9] On Self-adaptive Resource Allocation through Reinforcement Learning
    Panerati, Jacopo
    Sironi, Filippo
    Carminati, Matteo
    Maggio, Martina
    Beltrame, Giovanni
    Gmytrasiewicz, Piotr J.
    Sciuto, Donatella
    Santambrogio, Marco D.
    [J]. 2013 NASA/ESA CONFERENCE ON ADAPTIVE HARDWARE AND SYSTEMS (AHS), 2013, : 23 - 30
  • [10] Self-Adaptive Software Systems through Exploratory Changes
    Stavru, Stavros
    Ilieva, Sylvia
    [J]. THIRD INTERNATIONAL CONFERENCE ON SOFTWARE, SERVICES AND SEMANTIC TECHNOLOGIES S3T 2011, 2011, 101 : 215 - 216