Model-Driven integration and analysis of Access-control policies in Multi-layer information systems

3Citations
Citations of this article
10Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

Security is a critical concern for any information system. Security properties such as confidentiality, integrity and availability need to be enforced in order to make systems safe. In complex environments, where information systems are composed of a number of heterogeneous subsystems, each must participate in their achievement. Therefore, security integration mechanisms are needed in order to 1) achieve the global security goal and 2) facilitate the analysis of the security status of the whole system. For the specific case of access-control, access-control policies may be found in several components (databases, networks and applications) all, supposedly, working together in order to meet the high level security property. In this work we propose an integration mechanism for access-control policies to enable the analysis of the system security. We rely on model-driven technologies and the XACML standard to achieve this goal.

Cite

CITATION STYLE

APA

Martínez, S., Garcia-Alfaro, J., Cuppens, F., Cuppens-Boulahia, N., & Cabot, J. (2015). Model-Driven integration and analysis of Access-control policies in Multi-layer information systems. In IFIP Advances in Information and Communication Technology (Vol. 455, pp. 218–233). Springer New York LLC. https://doi.org/10.1007/978-3-319-18467-8_15

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free