• DocumentCode
    1930992
  • Title

    A security model for personal information security management based on partial approximative set theory

  • Author

    Csajbók, Zoltán

  • Author_Institution
    Dept. of Health Inf., Univ. of Debrecen, Nyíregyháza, Hungary
  • fYear
    2010
  • fDate
    18-20 Oct. 2010
  • Firstpage
    839
  • Lastpage
    845
  • Abstract
    Nowadays, computer users especially run their applications in a complex open computing environment which permanently changes in the running time. To describe the behavior of such systems, we focus solely on externally observable execution traces generated by the observed computing system. In these extreme circumstances the pattern of sequences of primitive actions (execution traces) which is observed by an external observer cannot be designed and/or forecast in advance. We have also taken into account in our framework that security policies are partial-natured. To manage the outlined problem we need tools which are approximately able to discover secure or insecure patterns in execution traces based on presupposes of computer users. Rough set theory may be such a tool. According to it, the vagueness of a subset of a finite universe U is defined by the difference of its lower and upper approximations with respect to a partition of the universe U. Using partitions, however, is a very strict requirement. In this paper, our starting point will be an arbitrary family of subsets of U. Neither that this family of sets covers the universe nor that the universe is finite will be assumed. This new approach is called the partial approximative set theory. We will apply it to build up a new security model for distributed software systems solely focusing on their externally observable executions and to find out whether the observed system is secure or not.
  • Keywords
    open systems; rough set theory; security of data; external observer; open computing environment; partial approximative set theory; personal information security management; rough set theory; security model; Approximation methods; Information security; Safety; Set theory; Software systems;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Science and Information Technology (IMCSIT), Proceedings of the 2010 International Multiconference on
  • Conference_Location
    Wisla
  • ISSN
    2157-5525
  • Print_ISBN
    978-1-4244-6432-6
  • Type

    conf

  • DOI
    10.1109/IMCSIT.2010.5679939
  • Filename
    5679939