Digital flight plans for server access control: Restricting anomalous activity with path-based declarations of intentions

Ronald Loui, Lucinda Caughey

2016 IEEE International Carnahan Conference on Security Technology (ICCST)(2016)

引用 1|浏览0
暂无评分
摘要
In response to increasing threats of malicious activity and data loss on servers, we propose a different and practical strategy for access control modeled after flight plans for pilots, which mixes existing role-based, object-based, and intention-based access models; it supports much finer grained, real-time, sequence-oriented anomaly detection. Users are required to declare their intended “flight path” in advance, a sketch of resource use: this may vary in detail, but could include database tables, file system directories, byte and bandwidth limits, use of encryption and archive creation, command sets, connection time, number and origin of connections, and ports. Sequence information provides especially strong constraint, even if it incomplete. We find an important place for active, on-line human sampling of flight plans, as well as pre-authorization for non-standard paths, and alerts for deviation from path. We also find a place for improved user profiling and a paradigm shift from ex-post log-based reconstruction of user activity to ex-ante declaration.
更多
查看译文
关键词
server access,access control,data loss prevention,intention recognition,privileges,computer security,specification,route,waypoints,flight plan,sequential constraint,anomaly detection
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要