• DocumentCode
    2206618
  • Title

    Privacy-Aware Access Control and Authorization in Passive Network Monitoring Infrastructures

  • Author

    Gogoulos, Fotios ; Antonakopoulou, Anna ; Lioudakis, Georgios V. ; Mousas, Aziz S. ; Kaklamani, Dimitra I. ; Venieris, Iakovos S.

  • Author_Institution
    Sch. of Electr. & Comput. Eng., Nat. Tech. Univ. of Athens, Athens, Greece
  • fYear
    2010
  • fDate
    June 29 2010-July 1 2010
  • Firstpage
    1114
  • Lastpage
    1121
  • Abstract
    Despite the usefulness of passive network monitoring for the operation, maintenance, control and protection of communication networks, as well as law enforcement, network monitoring activities are surrounded by serious privacy implications. In this paper, an innovative approach for privacy-preserving authorization and access control to data originating from passive network monitoring is described. The proposed framework relies on an ontological model for the specification of the access control policies, which are evaluated and enforced on a two-phase and two-stage basis by a system that intercedes between the network link and the monitoring applications. The two stages refer to controlled access regarding both the data that are disclosed to the monitoring application from the mediating system and the raw data that the mediator retrieves from the network link. On the other hand, the two phases concern respectively the execution of “static” and “dynamic” control; the former enforces the rules that are a priori applicable, grounded on the data, role and purpose semantics, while the latter evaluates the real-time contextual parameters for the adaptation of the access control procedures to the particular conditions underlying a request.
  • Keywords
    authorisation; computer network security; data privacy; ontologies (artificial intelligence); access control; access control policies; communication networks protection; mediating system; ontological model; passive network monitoring infrastructure; privacy aware access control; privacy preserving authorization; real-time contextual parameters; Authorization; Cognition; Iron; Monitoring; Ontologies; Passive networks; access control; authorisation; passive network monitoring; privacy; semantic information model;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer and Information Technology (CIT), 2010 IEEE 10th International Conference on
  • Conference_Location
    Bradford
  • Print_ISBN
    978-1-4244-7547-6
  • Type

    conf

  • DOI
    10.1109/CIT.2010.203
  • Filename
    5578562