Components- Based Access Control Architecture
TL;DR: Using usability testing, the evaluation of CACA showed 92% reduction in insider abuses and misuse of privileges, and shows that CACA can provide higher level of security access as against what used to exist.
read more
Abstract: Ensuring adequate security of information has been a growing concern of individuals and organizations. There is then the need to provide suitable access control mechanism for preventing insider abuses and ensuring appropriate use of resour ces. This paper presents an access control scheme that adopts the techniques of Role-Based Access Control (RBAC), Purpose-Based Access Control (PBAC), Time-Based Access Control (TBAC) and History-Based Access Control (HBAC) as components to form an integrated Components-based Access Control Architecture (CACA). In CACA, an Access Control Score (ACS) is computed from the combined access control techniques. CACA also combines ACS with the sensitivity nature of system resources before a level of access is granted. The architecture wa s implemented within a payroll system developed using JAVA and SQL. Using usability testing, t he evaluation of CACA showed 92% reduction in insider abuses and misuse of privileges. Th is shows that CACA can provide higher level of security access as against what used to exist.
read more
Chat with Paper
AI Agents for this Paper
Find similar papers on Google Scholar, PubMed and Arxiv
Write a critical review of this paper
Analyze citations of this paper to find unaddressed research gaps
Citations
Patent
Transparent control of access invoking real-time analysis of the query history
Hasso Plattner,Matthieu-Patrick Schapranow +1 more
- 22 May 2013
TL;DR: In this paper, a method for granting an inquirer querying a repository access to the repository, a communication protocol between a client and a server, and a system for controlling access of at least one inquirer to a repository are described.
90
Security-aware web service composition approaches: state-of-the-art
Homa Movahednejad,Suhaimi Ibrahim,Mahdi Sharifi,Harihodin Selamat,Sayed Gholam Hassan Tabatabaei +4 more
- 05 Dec 2011
TL;DR: This paper aims to present an exclusive taxonomy regarding service composition and apply it to categorize composition based approaches with respects to security issues as focus of this study.
9
Preventing Social Engineering and Espionage in Collaborative Knowledge Management Systems (KMSs)
TL;DR: The authors provide an Espionage Prevention Model (EP) that uses Semantic web-based annotations on knowledge assets to store relevant information and compares it to the Friend-Of-A-Friend data of the potential recipient of the resource.
9
A Fuzzy Multi-Criteria Decision-Making Method for Managing Network Security Risk Perspective
Suhel Ahmad Khan,Waris Khan,Dhirendra Pandey +2 more
- 01 Jan 2021
TL;DR: In this chapter, the author has depicted the significant measures and parameters with respect to huge industry/organizational prerequisites for building up a secure network.
3
Context Dependent Threat-Based Access Control System
TL;DR: This work presents a Context Dependent Threat-Based Access Control (CDTAC) system for correcting problems of unauthorized access and misuse of privileges and adopts relative probability in the estimation of the threat level of the contextual parameters.
References
Assessment of Access Control Systems
Vincent C. Hu,David F. Ferraiolo,D. Rick Kuhn +2 more
- 31 Aug 2006
TL;DR: This publication explains some of the commonly used access control services available in information technology systems, including role-based access control, which allows the creator of a file to delegate access to others and is one of the simplest examples of a model.
Assessment of Access Control Systems
Vincent C. Hu,David F. Ferraiolo,D. R. Kuhn,William Jeffrey,Carlos M Gutierrez,Robert Cresanti +5 more
- 31 Aug 2006
TL;DR: This publication explains some of the commonly used access control services available in information technology systems, including role-based access control, which allows the creator of a file to delegate access to others and is one of the simplest examples of a model.
161
A Purpose-Based Access Control Model
Naikuo Yang,Howard Barringer,Ning Zhang +2 more
- 29 Aug 2007
TL;DR: This paper presents a mechanism to specify privacy policy using VDM, the entities in the purpose-based access control model are specified, the invariants corresponding to the privacy requirements in privacy policy arespecified, and the operations in the model and their proof obligations are defined and investigated.
86
Static analysis of role-based access control in J2EE applications
Gleb Naumovich,Paolina Centonze +1 more
TL;DR: This work describes a new technique for analysis of Java 2, Enterprise Edition (J2EE) applications that uses points-to analysis to determine which object fields are accessed by which EJB methods, directly or indirectly.
47
Related Papers (5)
Sejong Oh
- 16 Jun 2007
Qing-hai Bai,Ying Zheng +1 more
- 26 Jul 2011
Zhiming Liu,Charles Morisset,Volker Stolz +2 more
- 13 Oct 2008