DocumentCode :
2302361
Title :
Trust-aware access control: How recent is your transaction history?
Author :
Ahmed, Ali ; Alnajem, Abdullah
Author_Institution :
Sch. of Inf. Technol., Monash Univ., Bandar Sunway, Malaysia
fYear :
2012
fDate :
16-18 May 2012
Firstpage :
208
Lastpage :
213
Abstract :
Establishing trust in a subject requesting access to a sensitive resource object is fundamental in history-aware access control models. A subject´s past behaviour could be used as an indication about the subject´s trustworthiness. In fact, a subject´s trust plays a significant role in deciding the associated access rights in, for example, context-aware access control models. Recently, there have been efforts to accommodate the subject´s trust level to provide smart security services including access control. Some proposals utilise data mining techniques, whereas some incorporate statistical methods to compute the subject´s trust value. Most of the models fail to identify malicious attempts from genuine subjects. In this paper, we propose a new model that bridges the gap by incorporating the concepts of Recency, Frequency and Sensitivity (RFS) in trust computation. The model is formally defined and prototyped in Java using the XACML RBAC profile and its run-time performance is investigated. The results show the model adds a significant overhead on top of the RBAC core model. However, the trust computation process could be done off-line cutting down that overhead dramatically, thus providing an affordable solution.
Keywords :
Java; access control; data mining; security of data; Java; RBAC core model; RFS; XACML RBAC; context-aware access control models; data mining techniques; history-aware access control models; recency frequency and sensitivity; run-time performance; smart security services; transaction history; trust computation process; trust-aware access control; trustworthiness; Access control; Computational modeling; History; Peer to peer computing; Proposals; Sensitivity;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Digital Information and Communication Technology and it's Applications (DICTAP), 2012 Second International Conference on
Conference_Location :
Bangkok
Print_ISBN :
978-1-4673-0733-8
Type :
conf
DOI :
10.1109/DICTAP.2012.6215352
Filename :
6215352
Link To Document :
بازگشت