Title :
LRBAC: Flexible function-level hierarchical role based access control for Linux
Author :
Javad Zandi;Abbas Naderi-Afooshteh
Author_Institution :
Department of Electrical and Computer Engineering, Shahid Beheshti University, Tehran, Iran
Abstract :
We present a flexible hierarchical role based access control model based on simple and existing technologies that enables efficient function-level access control, prototyped in a system called LRBAC1, a Linux kernel module enforcing access control over program execution. The hierarchical design allows for easy maintenance of roles and access rights in an organization, effectively thwarting access control vulnerabilities when configured using adequate policies. Though the prototype incurs significant overhead on background and small applications in current flexible deployment model, it incurs only 3.26% overhead on user interactions with the system (i.e interactive applications) and 14.4% overhead on Apache web server.
Keywords :
"Access control","Computational modeling","Prototypes","Organizations","Adaptation models","Standards organizations"
Conference_Titel :
Information Security and Cryptology (ISCISC), 2015 12th International Iranian Society of Cryptology Conference on
DOI :
10.1109/ISCISC.2015.7387894