DocumentCode :
2206618
Title :
Privacy-Aware Access Control and Authorization in Passive Network Monitoring Infrastructures
Author :
Gogoulos, Fotios ; Antonakopoulou, Anna ; Lioudakis, Georgios V. ; Mousas, Aziz S. ; Kaklamani, Dimitra I. ; Venieris, Iakovos S.
Author_Institution :
Sch. of Electr. & Comput. Eng., Nat. Tech. Univ. of Athens, Athens, Greece
fYear :
2010
fDate :
June 29 2010-July 1 2010
Firstpage :
1114
Lastpage :
1121
Abstract :
Despite the usefulness of passive network monitoring for the operation, maintenance, control and protection of communication networks, as well as law enforcement, network monitoring activities are surrounded by serious privacy implications. In this paper, an innovative approach for privacy-preserving authorization and access control to data originating from passive network monitoring is described. The proposed framework relies on an ontological model for the specification of the access control policies, which are evaluated and enforced on a two-phase and two-stage basis by a system that intercedes between the network link and the monitoring applications. The two stages refer to controlled access regarding both the data that are disclosed to the monitoring application from the mediating system and the raw data that the mediator retrieves from the network link. On the other hand, the two phases concern respectively the execution of “static” and “dynamic” control; the former enforces the rules that are a priori applicable, grounded on the data, role and purpose semantics, while the latter evaluates the real-time contextual parameters for the adaptation of the access control procedures to the particular conditions underlying a request.
Keywords :
authorisation; computer network security; data privacy; ontologies (artificial intelligence); access control; access control policies; communication networks protection; mediating system; ontological model; passive network monitoring infrastructure; privacy aware access control; privacy preserving authorization; real-time contextual parameters; Authorization; Cognition; Iron; Monitoring; Ontologies; Passive networks; access control; authorisation; passive network monitoring; privacy; semantic information model;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer and Information Technology (CIT), 2010 IEEE 10th International Conference on
Conference_Location :
Bradford
Print_ISBN :
978-1-4244-7547-6
Type :
conf
DOI :
10.1109/CIT.2010.203
Filename :
5578562
Link To Document :
بازگشت