首页> 外文期刊>International journal of systems assurance engineering and management >A cloud-user behavior assessment based dynamic access control model
【24h】

A cloud-user behavior assessment based dynamic access control model

机译:基于云用户行为评估的动态访问控制模型

获取原文
获取原文并翻译 | 示例
           

摘要

In traditional role-based access control (RBAC) model, the permission is bound with identity statically, without being dynamically adjusted by user behavior. Cloud users distribute widely and constitute complex and have legitimate identity whose behavior may be incredible, but any attack is achieved through malicious behavior. The cloud-user behavior assessment based dynamic access control model was proposed by introducing user behavior risk value, user trust degree and other factors into RBAC. First, the times of threat behavior was introduced into the information security risk equation to improve the accuracy of user behavior risk value. Then, both the times of threat behavior and the uneven interval of risk threshold were introduced the trust model based on behavior risk evolution to improve the accuracy of user trust degree. Finally, the dynamic authorization was achieved by mapping trust level and permissions. By the simulation experiment in a small campus cloud system, it can be shown that the change of user behavior risk value and user trust degree is more rational under different times and frequencies of threat behavior, and dynamic authorization is flexible by mapping the risk level and the user permissions.
机译:在传统的基于角色的访问控制(RBAC)模型中,权限与身份静态绑定,而不受用户行为的动态调整。云用户分布广泛,构成复杂且具有合法身份,其行为可能令人难以置信,但是任何攻击都是通过恶意行为来实现的。通过将用户行为风险值,用户信任度等因素引入RBAC,提出了一种基于云用户行为评估的动态访问控制模型。首先,将威胁行为的时间引入信息安全风险方程中,以提高用户行为风险值的准确性。然后,基于行为风险演化,引入了威胁行为的次数和风险阈值的不均匀间隔,以提高用户信任度的准确性。最后,通过映射信任级别和权限来实现动态授权。通过在小型校园云系统中的仿真实验,可以看出,在威胁行为的时间和频率不同的情况下,用户行为风险值和用户信任度的变化更为合理,通过映射风险级别和风险级别可以灵活地进行动态授权。用户权限。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号