Title :
Access control scheme for Web services ( ACSWS )
Author_Institution :
Fac. of Comput., Alghurair Univ., Dubai
Abstract :
The development and the wide spread use of web services allow for convenient electronic data storage and distribution all over the world. As this web services is a new service-oriented computing paradigm which poses the unique security challenges due to its inherent heterogeneity, multi-domain characteristic and highly dynamic nature. A key challenge in Web services security is to design effective access control schemes. However, most current access control systems base authorization decisions on subjectpsilas identity. In this paper, we suggest web access control scheme which incorporating user password and web server log. The major objective of the proposed model is to provide mechanisms to allow control of web user access based on the user access behavior by tracking the web access history. The system controls access to web pages depending on user password, date of last request, page visited (URL) and status action. The active userpsilas access pattern is matched with user access data discovered from user access history, based on mining web usage data using association rules mining and PrefixSpan algorithms, then analyzed to make the access control decision (web access is permitted or denied).
Keywords :
Web services; access control; data mining; security of data; PrefixSpan algorithms; Web pages; Web server log; Web services security; access control; association rules mining; data mining; electronic data storage; service-oriented computing; user access data; user password; Access control; Authorization; Control systems; Data mining; Data security; History; Memory; Web pages; Web server; Web services; Access Control; PrefixSpan; Web Mining; Web Sevices; Web Usage Mining;
Conference_Titel :
Computer and Communication Engineering, 2008. ICCCE 2008. International Conference on
Conference_Location :
Kuala Lumpur
Print_ISBN :
978-1-4244-1691-2
Electronic_ISBN :
978-1-4244-1692-9
DOI :
10.1109/ICCCE.2008.4580726