Towards Adaptive Access Control - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2018

Towards Adaptive Access Control

Andrea Margheri
  • Fonction : Auteur
  • PersonId : 1040483
Federica Paci
  • Fonction : Auteur
  • PersonId : 1040484
Vladimiro Sassone
  • Fonction : Auteur
  • PersonId : 1040485

Résumé

Access control systems are nowadays the first line of defence of modern IT systems. However, their effectiveness is often compromised by policy miscofigurations that can be exploited by insider threats. In this paper, we present an approach based on machine learning to refine attribute-based access control policies in order to reduce the risks of users abusing their privileges. Our approach exploits behavioral patterns representing how users typically access resources to narrow the permissions granted to users when anomalous behaviors are detected. The proposed solution has been implemented and its effectiveness has been experimentally evaluated using a synthetic dataset.
Fichier principal
Vignette du fichier
470961_1_En_7_Chapter.pdf (357.29 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01954403 , version 1 (13-12-2018)

Licence

Paternité

Identifiants

Citer

Luciano Argento, Andrea Margheri, Federica Paci, Vladimiro Sassone, Nicola Zannone. Towards Adaptive Access Control. 32th IFIP Annual Conference on Data and Applications Security and Privacy (DBSec), Jul 2018, Bergamo, Italy. pp.99-109, ⟨10.1007/978-3-319-95729-6_7⟩. ⟨hal-01954403⟩
54 Consultations
46 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More