UWSpace is currently experiencing technical difficulties resulting from its recent migration to a new version of its software. These technical issues are not affecting the submission and browse features of the site. UWaterloo community members may continue submitting items to UWSpace. We apologize for the inconvenience, and are actively working to resolve these technical issues.
 

A Dynamic Risk-Based Access Control Approach: Model and Implementation

dc.contributor.authorSavinov, Sergey
dc.date.accessioned2017-05-18T15:17:11Z
dc.date.available2017-05-18T15:17:11Z
dc.date.issued2017-05-18
dc.date.submitted2017-05-12
dc.description.abstractAccess control (AC) refers to mechanisms and policies that restrict access to resources, thus regulating access to physical or virtual resources of an information system. AC approaches are used to represent these mechanisms and policies by which users are granted access and specific access privileges to the resources or information of the system for which AC is provided. Traditional AC approaches encompass a variety of widely used approaches, including attribute-based access control (ABAC), mandatory access control (MAC), discretionary access control (DAC) and role-based access control (RBAC). Emerging AC approaches include risk adaptive access control (RAdAC), an approach that suggests that AC can adapt depending on specific situations. However, traditional and emerging AC approaches rely on static pre-defined risk mitigation tasks and do not support the adaptation of an AC risk mitigation process (RMP). There are no provided mechanisms and automated support that allow AC approaches to construct RMPs and to adapt to provide more flexible, custom-tailored responses to specific situations in order to minimize risks. Further, although existing AC approaches can operate in several knowledge domains at once, they do not explicitly take into account the relationships among risks related to different dimensions, e.g., security, productivity. In addition, although in the real world, risks accumulate over time, existing AC approaches do not appropriately provide means for risk resolution in situations in which risks accumulate as different, dangerous tasks impact risk measures. This thesis presents the definition, the implementation, and the application through two case studies of a novel AC risk-mitigation approach that combines dynamic RMP construction and risk assessment extended to include forecasting based on multiple risk-related utilities and events; provides support for a dynamic risk assessment that depends on one or multiple risk dimensions (e.g., security and productivity); offers cumulative risk assessment in which each action of interest can impact the risk-related utilities in a dynamic way; and presents an implementation of an adaptive simulation method based on risk-related utilities and events.en
dc.identifier.urihttp://hdl.handle.net/10012/11917
dc.language.isoenen
dc.pendingfalse
dc.publisherUniversity of Waterlooen
dc.subjectrisken
dc.subjectRAdACen
dc.subjectaccess controlen
dc.subjectbenefiten
dc.subjectmitigationen
dc.subjectremediationen
dc.subjectdynamicen
dc.subjectadaptiveen
dc.subjectimplementationen
dc.subjectautomateden
dc.subjectutilityen
dc.subjectprocess constructionen
dc.subjectquantitativeen
dc.subjectobligationen
dc.subjectresourcesen
dc.subjectprocessen
dc.subjecttask sequenceen
dc.subjectforecastingen
dc.subjectprojectionen
dc.subjecteventsen
dc.subjectdomainen
dc.subjectframeworken
dc.subjectsoftware developmenten
dc.subjectruntimeen
dc.subjectreal-timeen
dc.subjectprivacyen
dc.subjectaccumulationen
dc.subjectalternativeen
dc.subjectcriticalen
dc.subjectaccess denialen
dc.subjectdenyen
dc.subjectinformation leaken
dc.subjectsocial engineeringen
dc.subjectXACMLen
dc.subjectinformation securityen
dc.subjectrisk analysisen
dc.subjectrisk assessmenten
dc.titleA Dynamic Risk-Based Access Control Approach: Model and Implementationen
dc.typeDoctoral Thesisen
uws-etd.degreeDoctor of Philosophyen
uws-etd.degree.departmentDavid R. Cheriton School of Computer Scienceen
uws-etd.degree.disciplineComputer Scienceen
uws-etd.degree.grantorUniversity of Waterlooen
uws.comment.hiddenCorrect thesis title is:A Dynamic Risk-Based Access Control Approach: Model and Implementation. The other title was previously used, however my PhD committee requested a title change and MGO erroneously used old title in their Doctoral thesis acceptance form. I have requested a corrected Doctoral thesis acceptance form, however it will be only ready on May 18'th. Please check everything else, but the title, you will get a new form soon.en
uws.contributor.advisorPaulo, Alencar
uws.contributor.advisorBerry, Daniel
uws.contributor.affiliation1Faculty of Mathematicsen
uws.peerReviewStatusUnrevieweden
uws.published.cityWaterlooen
uws.published.countryCanadaen
uws.published.provinceOntarioen
uws.scholarLevelGraduateen
uws.typeOfResourceTexten

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Savinov_Sergey.pdf
Size:
3.62 MB
Format:
Adobe Portable Document Format
Description:
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
6.17 KB
Format:
Item-specific license agreed upon to submission
Description: