Towards more pro-active access control in computer systems and networks. Issue 49 (March 2015)
- Record Type:
- Journal Article
- Title:
- Towards more pro-active access control in computer systems and networks. Issue 49 (March 2015)
- Main Title:
- Towards more pro-active access control in computer systems and networks
- Authors:
- Zhang, Yixuan
He, Jingsha
Zhao, Bin
Huang, Zhiqing
Liu, Ruohong - Abstract:
- Abstract: Access control is a core security technology which has been widely used in computer systems and networks to protect sensitive information and critical resources and to counter malicious attacks. Although many access control models have been developed in the past, such as discretionary access control (DAC), mandatory access control (MAC) and role-based access control (RBAC), these models are designed primarily as a defensive measure in that they are used for examining access requests and making authorization decisions based on established access control policies. As the result, even after a malicious access is identified, the requester can still keep issuing more malicious access requests without much fear of punitive consequences from the access control system in subsequent accesses. Such access control may be acceptable in closed systems and networks but is not adequate in open systems and networks where the real identities and other critical information about requesters may not be known to the systems and networks. In this paper, we propose to design pro-active access control so that access control systems can respond to malicious access pro-actively to suit the needs of open systems and networks. We will first apply some established principles in the Game Theory to analyze current access control models to identify the limitations that make them inadequate in open systems and networks. To design pro-active access control (PAC), we incorporate a constraintAbstract: Access control is a core security technology which has been widely used in computer systems and networks to protect sensitive information and critical resources and to counter malicious attacks. Although many access control models have been developed in the past, such as discretionary access control (DAC), mandatory access control (MAC) and role-based access control (RBAC), these models are designed primarily as a defensive measure in that they are used for examining access requests and making authorization decisions based on established access control policies. As the result, even after a malicious access is identified, the requester can still keep issuing more malicious access requests without much fear of punitive consequences from the access control system in subsequent accesses. Such access control may be acceptable in closed systems and networks but is not adequate in open systems and networks where the real identities and other critical information about requesters may not be known to the systems and networks. In this paper, we propose to design pro-active access control so that access control systems can respond to malicious access pro-actively to suit the needs of open systems and networks. We will first apply some established principles in the Game Theory to analyze current access control models to identify the limitations that make them inadequate in open systems and networks. To design pro-active access control (PAC), we incorporate a constraint mechanism that includes feedback and evaluation components and show based on the Game Theory how to make such access control respond to malicious access in a pro-active manner. We also present a framework design of PAC and demonstrate through the implementation of trust-based access control the feasibility of design, implementation and application of pro-active access control. Such kind of models and mechanisms can serve as the foundation for the design of access control systems that will be made more effective in deterring malicious attacks in open systems and networks. Highlights: We analyzed current access control models to identify their drawbacks. We proposed pro-active access control for open systems and networks. We based our design and analysis on well-established principles in the Game Theory. We used trust-based access control to demonstrate the feasibility of our proposal. … (more)
- Is Part Of:
- Computers & security. Issue 49(2015)
- Journal:
- Computers & security
- Issue:
- Issue 49(2015)
- Issue Display:
- Volume 49, Issue 49 (2015)
- Year:
- 2015
- Volume:
- 49
- Issue:
- 49
- Issue Sort Value:
- 2015-0049-0049-0000
- Page Start:
- 132
- Page End:
- 146
- Publication Date:
- 2015-03
- Subjects:
- Security -- Access control -- Game theory -- Evaluation -- Payoffs -- Trust
Computer security -- Periodicals
Electronic data processing departments -- Security measures -- Periodicals
005.805 - Journal URLs:
- http://www.sciencedirect.com/science/journal/01674048 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.cose.2014.12.001 ↗
- Languages:
- English
- ISSNs:
- 0167-4048
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 3394.781000
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 5323.xml