• DocumentCode
    2486861
  • Title

    Anomaly analysis for Physical Access Control security configuration

  • Author

    Fitzgerald, William M. ; Turkmen, Fatih ; Foley, Simon N. ; O´Sullivan, Barry

  • fYear
    2012
  • fDate
    10-12 Oct. 2012
  • Firstpage
    1
  • Lastpage
    8
  • Abstract
    Physical Access Controls, such as supervised doors, surveillance cameras and alarms, act as important points of demarcation between physical zones (areas/rooms) of different levels of trust. They do so by controlling personnel flow to and from areas in accordance with the enterprise security policy. A significant challenge in providing physical access control for (restricted) areas is attaining a degree of confidence that a Physical Access Control security configuration adequately addresses the threats. A misconfiguration may result in a threat of unapproved personnel access or the denial of approved personnel access to a restricted zone. In practice, Physical Access Control security configurations typically span multiple zones, involve many users and run to many thousands of access-control rules, and such complexity may increase the likelihood of misconfiguration. In this paper, a formal model for Physical Access Control security configurations is presented. This model, implemented in SAT, captures a number of unique anomalies specific to Physical Access Control domain. A preliminary set of experiments that evaluate our approach is presented.
  • Keywords
    alarm systems; authorisation; doors; trusted computing; video surveillance; PAC systems; SAT; access-control rules; alarms; anomaly analysis; confidence degree; enterprise security policy; personnel access threats; personnel flow control systems; physical access control security configuration; physical zones; restricted zone; supervised doors; surveillance cameras; trust levels; Access control; Buildings; Personnel; Radio frequency; Redundancy; Topology;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Risk and Security of Internet and Systems (CRiSIS), 2012 7th International Conference on
  • Conference_Location
    Cork
  • Print_ISBN
    978-1-4673-3087-9
  • Electronic_ISBN
    978-1-4673-3088-6
  • Type

    conf

  • DOI
    10.1109/CRISIS.2012.6378953
  • Filename
    6378953