Title of article :
A Formal Approach for Risk Assessment in RBAC Systems
Author/Authors :
Ma, Ji Christian Doppler Laboratory for Client-Centric Cloud Computing, Austria
From page :
2432
To page :
2451
Abstract :
Risk assessment and access control are important issues in cloud computing.In this paper, we propose a formal approach to risk assessment for RBAC Systems, in which access control decisions are taken after consideration of risk assessment. The risk assessment method considers partial orderings on objects and actions, which allow us to effectively capture the notions of importance of objects and criticality of actions and then to determine the risk of assigning a specific role to a specific user. We in particular consider the cases of permission assignment and delegation assignment.
Keywords :
Risk assessment , access control , RBAC , poset , security classification
Journal title :
Journal of J.UCS (Journal of Universal Computer Science)
Journal title :
Journal of J.UCS (Journal of Universal Computer Science)
Record number :
2715008
Link To Document :
بازگشت