Enhanced Multilevel Fuzzy Inference System for Risk Adaptive Hybrid RFID Access Control System

被引:3
作者
Suleiman, Dima [1 ]
Al-Zewairi, Malek [2 ]
Shaout, Adnan [3 ]
机构
[1] Univ Jordan, King Abdullah II Sch Informat Technol, Amman, Jordan
[2] Jordan Informat Secur & Digital Forens Res Grp, Amman, Jordan
[3] Univ Michigan, Elect & Comp Engn Dept, Dearborn, MI 48128 USA
关键词
fuzzy logic; fuzzy inference system; access control; RFID; security; multilevel; SECURITY; FRAMEWORK;
D O I
10.3991/ijoe.v18i04.27485
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Risk-based access control systems are part of identity management systems used to accommodate environments with needs for dynamic access control decisions. The risk value is subjected to overestimation or underestimation since it is measured qualitatively, thus; causing uncertainty problems, which was apparent in a previously proposed hybrid risk adaptive (HRA) access control system. Conversely, Fuzzy Inference Systems can deal with the uncertainty of measures and control the outcomes more precisely; therefore, a multilevel fuzzy inference system (HRA-MFIS) was proposed to replace the risk assessment model in HRA. This paper continues to improve the previous model by introducing an enhanced multilevel fuzzy inference system (EHRA-MFIS), which utilizes user behaviour and time analysis to detect anomalous access behaviour. Moreover, it improves the hybrid adaptive risk calculation module by adding authentication, classification and the degree of user anomalous behaviour to the risk calculation algorithm. The results show that the proposed model has smoothed out the transition between the different risk levels and enhanced the system's overall security by considering the failed authorization attempts and failed authentication attempts, asset classification, and user behaviour when calculating the risk level.
引用
收藏
页码:31 / 51
页数:21
相关论文
共 25 条
[1]   Towards the realisation of context-risk-aware access control in pervasive computing [J].
Ahmed, Ali ;
Zhang, Ning .
TELECOMMUNICATION SYSTEMS, 2010, 45 (2-3) :127-137
[2]  
Al-Zewairi M., 2011, 2011 IEEE Jordan Conference on Applied Electrical Engineering and Computing Technologies (AEECT), P272, DOI [DOI 10.1109/AEECT.2011, 10.1109/AEECT.2011.6132520, DOI 10.1109/AEECT.2011.6132520]
[3]  
Al-Zewairi M., 2017, ACIT 2017 INT AR C I
[4]   Multilevel Fuzzy Inference System for Risk Adaptive Hybrid RFID Access Control System [J].
Al-Zewairi, Malek ;
Suleiman, Dima ;
Shaout, Adnan .
2016 CYBERSECURITY AND CYBERFORENSICS CONFERENCE (CCC), 2016, :1-7
[5]   Risk adaptive hybrid RFID access control system [J].
Al-Zewairi, Malek ;
Alqatawna, Ja'far ;
Atoum, Jalal .
SECURITY AND COMMUNICATION NETWORKS, 2015, 8 (18) :3826-3835
[6]   Conceptual Framework Based On Type-2 Fuzzy Logic Theory for Predicting Childhood Obesity Risk [J].
Almohammadi, Khalid .
INTERNATIONAL JOURNAL OF ONLINE AND BIOMEDICAL ENGINEERING, 2020, 16 (03) :95-106
[7]   Overriding of access control in XACML [J].
Alqatawna, Ja'far ;
Rissanen, Erik ;
Sadighi, Babak .
EIGHTH IEEE INTERNATIONAL WORKSHOP ON POLICIES FOR DISTRIBUTED SYSTEMS AND NETWORKS - PROCEEDINGS, 2007, :87-+
[8]  
[Anonymous], 2014, INT J COMPUTER APPL, DOI DOI 10.5120/18758-0028
[9]   Security enhancement of the authenticated RFID security mechanism based on chaotic maps [J].
Benssalah, Mustapha ;
Djeddou, Mustapha ;
Drouiche, Karim .
SECURITY AND COMMUNICATION NETWORKS, 2014, 7 (12) :2356-2372
[10]  
Chen C., 2010, 2010 14 INT C COMP S, P110, DOI [10.1109/CSCWD.2010, DOI 10.1109/CSCWD.2010]