LAD: Learning Access Control Polices and Detecting Access Anomalies in Smart Environments

LAD: Learning Access Control Polices and Detecting Access Anomalies in Smart Environments
复制标题

DOI:
10.1109/mass.2019.00063
复制
发表时间:
2019-11
期刊:
2019 IEEE 16th International Conference on Mobile Ad Hoc and Sensor Systems (MASS)
影响因子:
--
通讯作者:
T. Kalbarczyk;Chenguang Liu;Jie Hua;C. Julien
T. Kalbarczyk;Chenguang Liu;Jie Hua;C. Julien
中科院分区:
其他
文献类型:
--
作者:
T. Kalbarczyk;Chenguang Liu;Jie Hua;C. Julien

文献摘要

相似文献

长期以来,访问控制领域在指定访问控制策略时缺乏表达能力。最近的方法利用上下文指纹来制定访问控制框架,用于生成和执行访问控制策略。然而,有效地和自动地识别与访问相关的上下文属性已被证明具有挑战性和繁琐。一种在支持更有表现力和易于使用的基于属性的访问控制方面显示出前景的方法依赖于连续邻居发现协议和低成本无线通信技术(诸如蓝牙低功耗(BLE))的最新进展。这些技术为构建智能环境创造了机会,这些环境可以无缝且廉价地提供丰富的上下文数据。这些功能有可能使新的透明和自动的方法来定义和评估移动的用户的访问控制策略,并在智能环境中检测异常的访问模式。在本文中,我们提出了LAD框架,使用原始的上下文数据,通过技术,如BLE推导出实时属性定义的存在下,移动的和静态节点在附近的环境。基于这些环境中的用户交互,我们的框架学习适当的访问控制策略,并根据用户在智能环境中移动时实时变化的属性执行这些策略。
The domain of access control has long suffered from a lack of expressiveness in specifying access control policies. Recent approaches have leveraged contextual fingerprinting to formulate access control frameworks for both generating and enforcing access control policies. However, effectively and automatically identifying the context attributes relevant for access has proven challenging and cumbersome. An approach that shows promise in supporting more expressive and easy-to-use attribute-based access control relies on recent advances in continuous neighbor discovery protocols and low cost wireless communication technologies such as Bluetooth Low Energy (BLE). These technologies have created opportunities to build smart environments that can seamlessly and inexpensively provide rich contextual data. These capabilities have the potential to enable new transparent and automatic approaches to defining and evaluating access control policies for mobile users and for detecting anomalous access patterns in smart environments. In this paper, we present the LAD framework that uses raw contextual data available via technologies such as BLE to derive real-time attributes defined by the presence of mobile and static nodes in the nearby environment. Based on user interactions in these environments, our framework learns appropriate access control policies and enforces these policies based on attributes that change in real-time as users move in the smart environment.