Self-Adaptive Role-Based Access Control for Business Processes.

SEAMS@ICSE(2017)

引用 22|浏览8
暂无评分
摘要
We present an approach for dynamically reconfiguring the role-based access control (RBAC) of information systems running business processes, to protect them against insider threats. The new approach uses business process execution traces and stochastic model checking to establish confidence intervals for key measurable attributes of user behaviour, and thus to identify and adaptively demote users who misuse their access permissions maliciously or accidentally. We implemented and evaluated the approach and its policy specification formalism for a real IT support business process, showing their ability to express and apply a broad range of self-adaptive RBAC policies.
更多
查看译文
关键词
adaptive role-based access control,business processes,probabilistic model checking,Markov models,insider threats
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要