A Dynamic Risk-based Access Control Model for Cloud Computing

被引:13
|
作者
Chen, Aiguo [1 ]
Xing, Hanwen [1 ]
She, Kun [2 ]
Duan, Guiduo [1 ]
机构
[1] Univ Elect Sci & Technol China, Sch Comp Sci & Engn, Chengdu 611731, Peoples R China
[2] Univ Elect Sci & Technol China, Sch Informat & Software Engn, Chengdu 610054, Peoples R China
关键词
access control; risk assessment; ABAC; data stream;
D O I
10.1109/BDCloud-SocialCom-SustainCom.2016.90
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Cloud computing environment is full of massive resources and provides resource services to the outside environment. There are lots of resource access requests both from the dynamic internal environment of cloud and the uncontrollable external environment. Traditional access control method is being widely used in cloud computing, whose rule-based method leads to huge security risk and can't fulfill the security needs of the cloud. In this paper, a dynamic risk-based access control model (DRAC) is proposed, which emphasizes the risk measurement as an auxiliary decision indicator. Moreover, a dynamic threshold of the risk is derived from the history records, and the comprehensive final decision is affect by the policy, risk measurement and dynamic threshold. To improve performance, the sliding window calculation method based on data stream is adopted. Finally, we analyze the scalability and effectiveness of the model in cloud environment application.
引用
收藏
页码:579 / 584
页数:6
相关论文
共 50 条
  • [1] A Dynamic Risk-based Access Control Architecture for Cloud Computing
    dos Santos, Daniel Ricardo
    Westphall, Carla Merkle
    Westphall, Carlos Becker
    [J]. 2014 IEEE NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (NOMS), 2014,
  • [2] A Dynamic Risk and Role-based Access Control Model in Cloud Computing Environment
    Bai, Xin
    [J]. 2016 INTERNATIONAL CONFERENCE ON COMPUTER ENGINEERING, INFORMATION SCIENCE AND INTERNET TECHNOLOGY (CII 2016), 2016, : 14 - 20
  • [3] Dynamic Access Control Model for Cloud Computing
    Auxilia, M.
    Raja, K.
    [J]. 2014 SIXTH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING, 2014, : 47 - 56
  • [4] Risk Based Access Control In Cloud Computing
    Lakshmi, H.
    Namitha, S.
    Seemanthini
    Gopalan, Satheesh
    Sanjay, H. A.
    Chandrashekaran, K.
    Bhaskar, Atul
    [J]. 2015 INTERNATIONAL CONFERENCE ON GREEN COMPUTING AND INTERNET OF THINGS (ICGCIOT), 2015, : 1502 - 1505
  • [5] A framework and risk assessment approaches for risk-based access control in the cloud
    dos Santos, Daniel Ricardo
    Marinho, Roberto
    Schmitt, Gustavo Roecker
    Westphall, Carla Merkle
    Westphall, Carlos Becker
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2016, 74 : 86 - 97
  • [6] Dynamic Risk Access Control Model for Cloud Platform
    Xie, Lixia
    Wei, Ruixin
    Ning, Yuguang
    Yang, Hongyu
    [J]. CLOUD COMPUTING AND SECURITY, PT III, 2018, 11065 : 12 - 22
  • [7] CLOUD COMPUTING MODEL BASED ON MULTISERVICE ACCESS DYNAMIC DETECTION
    Zhu, Zhenyu
    Chen, Hui
    Wu, Lianguo
    [J]. 2014 IEEE 3rd International Conference on Cloud Computing and Intelligence Systems (CCIS), 2014, : 461 - 464
  • [8] A Fuzzy Modeling Approach for Risk-based Access Control in eHealth Cloud
    Li, Juan
    Bai, Yan
    Zaman, Nazia
    [J]. 2013 12TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2013), 2013, : 17 - 23
  • [9] Dynamic risk-based decision methods for access control systems
    Shaikh, Riaz Ahmed
    Adi, Kamel
    Logrippo, Luigi
    [J]. COMPUTERS & SECURITY, 2012, 31 (04) : 447 - 464
  • [10] An access control model for cloud computing
    Younis, Younis A.
    Kifayat, Kashif
    Merabti, Madjid
    [J]. JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2014, 19 (01) : 45 - 60