Ítem
Solo Metadatos

Dynamic Counter-measures for Risk-based Access Control Systems: An Evolutive Approach

dc.creatorDíaz López, Daniel Orlandospa
dc.creatorDólera-Tormo, Ginésspa
dc.creatorGómez-Mármol, Félixspa
dc.creatorMartínez-Pérez, Gregoriospa
dc.date.accessioned2020-08-19T14:42:41Z
dc.date.available2020-08-19T14:42:41Z
dc.date.created2016-02-01spa
dc.description.abstractRisk-based access control systems are a new element in access control categories, incorporating risk analysis as part of the inputs to consider when taking an authorization decision. A risk analysis over a resource leads generally to temporal allocation of the resource in a risk level (e.g. high, medium, low). Ideally, for each risk level and kind of resource, the access control system should take an authorization decision (expressed like a permit or deny) and the system administrator should also trigger specific counter-measures to protect resources according to their risk level. In a small access control system with few resources it is possible for an administrator to follow the risk level changes and react promptly with counter-measures; but in medium/large access control systems it is almost unfeasible to react in a customized way to thousands of risk level emergencies asking for attention. In this paper we propose the adoption of dynamic counter-measures (which can be integrated within access control policies) changing along time to face variations in the risk level of every resource, bringing two main benefits, namely: (i) a suitable resource protection according to the risk level (not under or over estimated) and (ii) an access control system granting/denying access depending on the fulfillment of a set of security controls applicable in an authorization access request. To define the most appropriate set of counter-measures applicable for a specific situation we define a method based on genetic algorithms, which allows to find a solution in a reasonable time frame satisfying different required conditions. Finally, the conducted experiments show the applicability of our proposal in a real scenario.eng
dc.format.mimetypeapplication/pdf
dc.identifier.doihttps://doi.org/10.1016/j.future.2014.10.012
dc.identifier.issnISSN: 0167-739X
dc.identifier.urihttps://repository.urosario.edu.co/handle/10336/27550
dc.language.isoengspa
dc.publisherElsevierspa
dc.relation.citationEndPage335
dc.relation.citationStartPage321
dc.relation.citationTitleFuture Generation Computer Systems
dc.relation.citationVolumeVol. 55
dc.relation.ispartofFuture Generation Computer Systems, ISSN: 0167-739X, Vol.55 (February, 2016); pp. 321-335spa
dc.relation.urihttps://www.sciencedirect.com/science/article/abs/pii/S0167739X14002052spa
dc.rights.accesRightsinfo:eu-repo/semantics/restrictedAccess
dc.rights.accesoRestringido (Acceso a grupos específicos)spa
dc.sourceFuture Generation Computer Systemsspa
dc.source.instnameinstname:Universidad del Rosario
dc.source.reponamereponame:Repositorio Institucional EdocUR
dc.subject.keywordISO 27001spa
dc.subject.keywordISMSspa
dc.subject.keywordRisk managementspa
dc.subject.keywordAccess control systemsspa
dc.subject.keywordGenetic algorithmsspa
dc.subject.keywordCounter-measuresspa
dc.titleDynamic Counter-measures for Risk-based Access Control Systems: An Evolutive Approachspa
dc.title.TranslatedTitleContramedidas dinámicas para sistemas de control de acceso basados ??en riesgos: un enfoque evolutivospa
dc.typearticleeng
dc.type.hasVersioninfo:eu-repo/semantics/publishedVersion
dc.type.spaArtículospa
Archivos
Colecciones