کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
424552 685587 2016 14 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
A web-based cooperative tool for risk management with adaptive security
ترجمه فارسی عنوان
یک ابزار تعاونی مبتنی بر وب برای مدیریت ریسک با امنیت تطبیقی
کلمات کلیدی
مدیریت ریسک تعاونی، امنیت سازگار، محیط، دامنه امنیت، ابزار ریسک مبتنی بر وب
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر نظریه محاسباتی و ریاضیات
چکیده انگلیسی


• We present a web-based cooperative tool for risk management with adaptive security.
• Based on a motivating scenario the risk and security elements are introduced.
• Security is built on the ABAC (Attribute Based Access Control) paradigm.
• A Risk Management System is illustrated that facilitates the cooperation in risk management.
• Using Event–Condition–Action meta-rules, dynamic authorization based on risk is controlled.

Risk management can benefit from Web-based tools fostering actions for treating risks in an environment, while having several individuals collaborating to face the endeavors related to risks. During the intervention, the security rules in place to preserve resources from unauthorized access, might need to be modified on the fly, e.g., increasing the privileges of risk managers or letting rescue teams view the exact position of the victims. Modifications should respect the overall security policies and avoid security conflicts. This paper presents a dynamic access control model for environmental risks involving physical resources. Data structures included in our Web application to represent both risk and security are given. To keep the dynamic security rules compliant with overall organization security objectives, we consider rules grouped in Access Control Domains so that changes do not create security conflicts during collaboration in risk management. Considering work environments as an example, risk and access control models are introduced. Security is built on the ABAC (Attribute Based Access Control) paradigm. A Risk Management System (RMS) is illustrated: it captures events, signals potential risks, and outputs strategies to prevent the risk. Dynamic authorization is included in the RMS to vary subjects’ privileges on physical resources based on risk level, people position and so on. These concepts are implemented in a prototype Web application appearing as a Web Dashboard for risk management.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Future Generation Computer Systems - Volume 54, January 2016, Pages 409–422
نویسندگان
, , ,