• DocumentCode
    2269663
  • Title

    Computing conspiracies [data integrity]

  • Author

    Elsas, Ph I. ; De Vries, P. M Ott ; van de Riet, R.P.

  • Author_Institution
    Free Univ., Amsterdam
  • fYear
    1998
  • fDate
    1998
  • Firstpage
    256
  • Lastpage
    266
  • Abstract
    The concept of `segregation of duties´ is well-known in both organisational and security contexts. For example, the Clark-Wilson model stresses the importance of such a policy appropriate for regulating the involvement of subjects in acting upon business information and business values. However, it gives no guidelines on how to distinguish a proper policy from an improper one. Furthermore, the discipline of auditing has developed numerous schemes for segregation of duties. In this paper we use a model that allows quantification of-and reasoning about-audit-technical segregation of duties. Our approach is based on normative (`Soll´) and actual (`Ist´) specifications of a company´s circular flow of business values in terms of enriched Petri nets. In this type of Petri net the markers represent money, goods, debts and registrations of these business values, the places represent their buffer locations and the transitions represent transformation procedures. Associated to these Petri net elements are agents and their authorisations and abilities. Undetectable use of company assets can now be modelled in the `Ist´ net by the general Petri net notion of `T-invariant´. The design of a proper scheme for segregation of duties then reduces to maximisation of the number of agents that need to be minimally involved in order to establish a firing of such a T-invariant
  • Keywords
    Petri nets; authorisation; data integrity; inference mechanisms; Clark-Wilson model; Petri nets; T-invariant; business information; business values; data integrity; quantification; reasoning; segregation of duties; Authorization; Companies; Electrical capacitance tomography; Europe; Guidelines; Petri nets; Protection; Read only memory; Security; Stress;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Database and Expert Systems Applications, 1998. Proceedings. Ninth International Workshop on
  • Conference_Location
    Vienna
  • Print_ISBN
    0-8186-8353-8
  • Type

    conf

  • DOI
    10.1109/DEXA.1998.707411
  • Filename
    707411