Extending RBAC for Large Enterprises and Its Quantitative Risk Evaluation

نویسندگان

  • Seiichi Kondo
  • Mizuho Iwaihara
  • Masatoshi Yoshikawa
  • Masashi Torato
چکیده

Systems and security products based on the RBAC model have been widely introduced to enterprises. Especially, the demands on enforcement of enterprise-level security policies and total identity management are rapidly growing. The RBAC model needs to be extended to deal with various circumstances of large enterprises, such as geographical distribution and heterogeneous environments including physical access control. In this paper, we introduce a new RBAC model, suitable for single sign-on systems. This model optimizes evaluation of rule-based RBAC so that total operation costs and productivity can be improved. Furthermore, to select most cost-effective RBAC extensions for enterprise-wide requirements, we propose a quantitative risk evaluation method based on fault trees. We construct fault trees having security violation and productivity loss as top events, and RBAC standard functions and security incidents as basic events. Probabilities of the top events are computed for given RBAC models and operation environments. We apply this method to a real enterprise system using the above RBAC extension and the proposed model realizes more safety and productivity over the base model. Seiichi Kondo, Mizuho Iwaihara, Masatoshi Yoshikawa, Masashi Torato 100

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

ESPOONERBAC: Enforcing security policies in outsourced environments

Data outsourcing is a growing business model offering services to individuals and enterprises for processing and storing a huge amount of data. It is not only economical but also promises higher availability, scalability, and more effective quality of service than in-house solutions. Despite all its benefits, data outsourcing raises serious security concerns for preserving data confidentiality....

متن کامل

A Model for Strategic Alliance Functions for Small and Medium-Sized Enterprises

This research aims at identifying and presenting a model for strategic alliance functions for successful small and medium-sized enterprises. The functions of strategic alliance include strengthening competitive advantage, strengthening entrepreneurial and innovative capabilities, strengthening social capital, and internationalization of small and medium-sized enterprises. Research method was bo...

متن کامل

Department of Computer Science and Engineering

Role-Based Access Control (RBAC) has proven as a cost effective as well as a practical solution for authorization management in large enterprises. In the recent past, RBAC has been widely explored and there have been several extensions to it. Current systems do not enforce standard RBAC features and its extensions in a seamless way, which is essential to make RBAC even better-suited for a wide ...

متن کامل

A FAMILY OF MODELS FOR RULE-BASED USER-ROLE ASSIGNMENT by

A FAMILY OF MODELS FOR RULE-BASED USER-ROLE ASSIGNMENT Mohammad Abdullah Al-Kahtani, Ph.D. George Mason University, 2003 Dissertation Director: Dr. Ravi Sandhu Conventional role based access control (RBAC) was designed with closed-enterprise environment in mind where a security officer(s) manually assigns users to roles. However, today, an increasing number of service-providing enterprises make...

متن کامل

A new approach for performance evaluation of energy-related enterprises

Oil is among the most effective and the largest industries in the world. Given that it supplies a large percentage of the world’s energy and plays a significant role in the national power and international credit of countries, it has a huge impact on our world today. Iran has  huge oil reserves, and plays a key role in the exchange of the required energy in the world. In order to improve the pe...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2008