• DocumentCode
    2325300
  • Title

    Access control scheme for Web services ( ACSWS )

  • Author

    Elsheikh, Selma

  • Author_Institution
    Fac. of Comput., Alghurair Univ., Dubai
  • fYear
    2008
  • fDate
    13-15 May 2008
  • Firstpage
    854
  • Lastpage
    858
  • Abstract
    The development and the wide spread use of web services allow for convenient electronic data storage and distribution all over the world. As this web services is a new service-oriented computing paradigm which poses the unique security challenges due to its inherent heterogeneity, multi-domain characteristic and highly dynamic nature. A key challenge in Web services security is to design effective access control schemes. However, most current access control systems base authorization decisions on subjectpsilas identity. In this paper, we suggest web access control scheme which incorporating user password and web server log. The major objective of the proposed model is to provide mechanisms to allow control of web user access based on the user access behavior by tracking the web access history. The system controls access to web pages depending on user password, date of last request, page visited (URL) and status action. The active userpsilas access pattern is matched with user access data discovered from user access history, based on mining web usage data using association rules mining and PrefixSpan algorithms, then analyzed to make the access control decision (web access is permitted or denied).
  • Keywords
    Web services; access control; data mining; security of data; PrefixSpan algorithms; Web pages; Web server log; Web services security; access control; association rules mining; data mining; electronic data storage; service-oriented computing; user access data; user password; Access control; Authorization; Control systems; Data mining; Data security; History; Memory; Web pages; Web server; Web services; Access Control; PrefixSpan; Web Mining; Web Sevices; Web Usage Mining;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer and Communication Engineering, 2008. ICCCE 2008. International Conference on
  • Conference_Location
    Kuala Lumpur
  • Print_ISBN
    978-1-4244-1691-2
  • Electronic_ISBN
    978-1-4244-1692-9
  • Type

    conf

  • DOI
    10.1109/ICCCE.2008.4580726
  • Filename
    4580726