ACCESS-CONTROL - PRINCIPLES AND PRACTICE

ACCESS-CONTROL - PRINCIPLES AND PRACTICE
复制标题

DOI:
10.1109/35.312842
复制
发表时间:
1994-09-01
影响因子:
11.2
通讯作者:
SAMARATI, P
SAMARATI, P
中科院分区:
计算机科学1区
文献类型:
--
作者:
SANDHU, RS;SAMARATI, P

文献摘要

被引文献

相似文献

访问控制限制用户可以直接做什么,以及允许代表用户执行的程序做什么。通过这种方式,访问控制旨在防止可能导致安全漏洞的活动。本文介绍访问控制及其与其他安全服务(如身份验证、审计和管理)的关系。然后,它回顾了访问矩阵模型,并描述了不同的方法来实现访问矩阵在实际系统中,并遵循与当前系统中常见的访问控制策略的讨论,并简要考虑访问控制管理。<>
Access control constrains what a user can do directly, as well as what programs executing on behalf of the users are allowed to do. In this way access control seeks to prevent activity that could lead to a breach of security. This article explains access control and its relationship to other security services such as authentication, auditing, and administration. It then reviews the access matrix model and describes different approaches to implementing the access matrix in practical systems, and follows with a discussion of access control policies commonly found in current systems, and a brief consideration of access control administration.<>