Title :
Access Control in Social Enterprise Applications: An Empirical Evaluation
Author :
Bhatti, Rajbir ; Gaspard, Camille ; Nita-Rotaru, Cristina
Abstract :
The social enterprise is reported as one of the biggest IT trends, and is only increasing in popularity. Many enterprises are adopting social media communication channels such as Yammer, Chatter, and Jive for collaboration amongst employees. One key concern however is the lack of user-level access control mechanisms in these applications. In particular, introducing social media applications in government, healthcare and financial sectors requires strict controls on which employees can access or share what kinds of company data based on various federal and state regulations. The existing vendor solutions do not provide fine-grained access control policies to support these requirements, and the impact of adding such policies to these applications have not been explored yet. In this work we provide an empirical evaluation of embedding fine-grained access control policies in Group Communication Systems (GCS) which serve as a mechanism for message exchange in social media applications. Our evaluation is based on a proposed framework for Role-Based Access Control for GCS in wide area networks (WAN) scenarios where the access control policies are specified and enforced using the X-RBAC policy framework. The main focus of this work is to evaluate the performance of our proposed framework and demonstrate that adding the access control mechanisms to an existing GCS incurs minimal overhead, looking especially at the challenges in WAN scenarios that are relevant to message exchange between geographically distributed employees in the enterprise. We show that with the use of caching, the proposed framework adds minimal overhead in WAN environments, while still providing the advantages of having such a framework built in the GCS´s interface to enable access control for the social enterprise.
Keywords :
authorisation; business data processing; cache storage; computer network security; social networking (online); wide area networks; Chatter; GCS; IT trends; Jive; WAN; X-RBAC policy framework; Yammer; caching; financial sectors; fine-grained access control policies; geographically distributed employees; government; group communication systems; healthcare sectors; message exchange; role-based access control; social enterprise applications; social media applications; social media communication channels; state regulations; user-level access control mechanisms; vendor solutions; wide area networks; Access control; Media; Peer-to-peer computing; Throughput; Wide area networks; XML;
Conference_Titel :
Distributed Computing Systems Workshops (ICDCSW), 2013 IEEE 33rd International Conference on
Conference_Location :
Philadelphia, PA
Print_ISBN :
978-1-4799-3247-4
DOI :
10.1109/ICDCSW.2013.4