DocumentCode :
2269663
Title :
Computing conspiracies [data integrity]
Author :
Elsas, Ph I. ; De Vries, P. M Ott ; van de Riet, R.P.
Author_Institution :
Free Univ., Amsterdam
fYear :
1998
fDate :
1998
Firstpage :
256
Lastpage :
266
Abstract :
The concept of `segregation of duties´ is well-known in both organisational and security contexts. For example, the Clark-Wilson model stresses the importance of such a policy appropriate for regulating the involvement of subjects in acting upon business information and business values. However, it gives no guidelines on how to distinguish a proper policy from an improper one. Furthermore, the discipline of auditing has developed numerous schemes for segregation of duties. In this paper we use a model that allows quantification of-and reasoning about-audit-technical segregation of duties. Our approach is based on normative (`Soll´) and actual (`Ist´) specifications of a company´s circular flow of business values in terms of enriched Petri nets. In this type of Petri net the markers represent money, goods, debts and registrations of these business values, the places represent their buffer locations and the transitions represent transformation procedures. Associated to these Petri net elements are agents and their authorisations and abilities. Undetectable use of company assets can now be modelled in the `Ist´ net by the general Petri net notion of `T-invariant´. The design of a proper scheme for segregation of duties then reduces to maximisation of the number of agents that need to be minimally involved in order to establish a firing of such a T-invariant
Keywords :
Petri nets; authorisation; data integrity; inference mechanisms; Clark-Wilson model; Petri nets; T-invariant; business information; business values; data integrity; quantification; reasoning; segregation of duties; Authorization; Companies; Electrical capacitance tomography; Europe; Guidelines; Petri nets; Protection; Read only memory; Security; Stress;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Database and Expert Systems Applications, 1998. Proceedings. Ninth International Workshop on
Conference_Location :
Vienna
Print_ISBN :
0-8186-8353-8
Type :
conf
DOI :
10.1109/DEXA.1998.707411
Filename :
707411
Link To Document :
بازگشت