Abstract
In a clear contrast with the phenomenal growth of Web database applications, access control issues related to data stored in the back-end databases have largely been neglected. Current approaches to access control on databases do not fit web databases because they are mostly based on individual user identities. In this paper, we propose (RBAC+), a dynamic access control model to enforce fine-grained access control to web databases. It extends the Role-Based Access Control model standard with the notions of application, application profile and sub-application session. The proposed dynamic access control model enhances the ability of detecting malicious transactions, the dominant cause that demolishes database system, by tracking application users throughout a whole session. Hence, attacks caused by malicious transactions can be detected and canceled timely before they succeed. © 2010 IEEE.
Author supplied keywords
Cite
CITATION STYLE
Bouchahda, A., Le Thanh, N., Bouhoula, A., & Labbene, F. (2010). RBAC+: Dynamic access control for RBAC-administered web-based databases. In Proceedings - 4th International Conference on Emerging Security Information, Systems and Technologies, SECURWARE 2010 (pp. 135–140). https://doi.org/10.1109/SECURWARE.2010.30
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.