A Framework for Threat Assessment in Access Control Systems

被引:0
作者
Khambhammettu, Hemanth [1 ]
Boulares, Sofiene [1 ]
Adi, Kamel [1 ]
Logrippo, Luigi [1 ]
机构
[1] Univ Quebec, Lab Rech Securite Informat, Outaouais, PQ, Canada
来源
INFORMATION SECURITY AND PRIVACY RESEARCH | 2012年 / 376卷
关键词
Security; Access control; Threat assessment;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
We describe a framework for threat assessment specifically within the context of access control systems, where subjects request access to resources for which they may not be pre-authorized. The framework that we describe includes four different approaches for conducting threat assessment: an object sensitivity-based approach, a subject trustworthiness-based approach and two additional approaches which are based on the difference between object sensitivity and subject trustworthiness. We motivate each of the four approaches with a series of examples. We also identify and formally describe the properties that are to be satisfied within each approach. Each of these approaches results in different threat orderings, and can be chosen based on the context of applications or preference of organizations.
引用
收藏
页码:187 / 198
页数:12
相关论文
共 10 条
  • [1] Bartsch S., 2010, Proceedings of the 3rd international conference on Security of information and networks, P62
  • [2] Fuzzy multi-level security : An experiment on quantified risk-adaptive access control - Extended abstract
    Cheng, Pau-Chen
    Rohatgi, Pankaj
    Keser, Claudia
    Karger, Paul A.
    Wagner, Grant M.
    Reninger, Angela Schuett
    [J]. 2007 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, PROCEEDINGS, 2007, : 222 - +
  • [3] Diep NN, 2007, ECUMN 2007: FOURTH EUROPEAN CONFERENCE ON UNIVERSAL MULTISERVICE NETWORKS, PROCEEDINGS, P419
  • [4] Kandala S., 2011, P 6 INT C AV REL SEC
  • [5] McGraw Robert, 2009, PRIV ACC MAN WORKSH, V25, P55
  • [6] Ni Q., 2010, P 5 ACM S INFORM COM, P250, DOI 10.1145/1755688.1755719
  • [7] NIST, 2008, NIST SPEC PUBL SP, VI
  • [8] NIST, 2002, NATL I STANDARDTEC, V800-30
  • [9] NIST, 2008, NIST SPEC PUBL SP, VII
  • [10] Wang Qingsong, 2011, Proceedings of the 2011 IEEE CIE International Conference on Radar (Radar), P406, DOI 10.1109/CIE-Radar.2011.6159563