RBAC+: Dynamic access control for RBAC-administered web-based databases

5Citations
Citations of this article
9Readers
Mendeley users who have this article in their library.
Get full text

Abstract

In a clear contrast with the phenomenal growth of Web database applications, access control issues related to data stored in the back-end databases have largely been neglected. Current approaches to access control on databases do not fit web databases because they are mostly based on individual user identities. In this paper, we propose (RBAC+), a dynamic access control model to enforce fine-grained access control to web databases. It extends the Role-Based Access Control model standard with the notions of application, application profile and sub-application session. The proposed dynamic access control model enhances the ability of detecting malicious transactions, the dominant cause that demolishes database system, by tracking application users throughout a whole session. Hence, attacks caused by malicious transactions can be detected and canceled timely before they succeed. © 2010 IEEE.

Cite

CITATION STYLE

APA

Bouchahda, A., Le Thanh, N., Bouhoula, A., & Labbene, F. (2010). RBAC+: Dynamic access control for RBAC-administered web-based databases. In Proceedings - 4th International Conference on Emerging Security Information, Systems and Technologies, SECURWARE 2010 (pp. 135–140). https://doi.org/10.1109/SECURWARE.2010.30

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free