Show simple item record

dc.contributor.authorLee, Brian
dc.contributor.authorVanickis, Roman
dc.contributor.authorRogelio, Franklin
dc.contributor.authorJacob, Paul
dc.date.accessioned2020-05-20T09:13:55Z
dc.date.available2020-05-20T09:13:55Z
dc.date.copyright2017
dc.date.issued2017-03
dc.identifier.citationLee, B., Vanickis, V., Rogelio, F., Jacob, P. (2017). Situational awareness based risk-adaptable access control in enterprise networks. In ICC '17: Proceedings of the Second International Conference on Internet of things, Data and Cloud Computing. Porto, Portugal. 16-17 June 2017.en_US
dc.identifier.isbn978-1-4503-4774-7
dc.identifier.otherConferences - Software Research Institute - AITen_US
dc.identifier.urihttp://research.thea.ie/handle/20.500.12065/3217
dc.description.abstractAs the computing landscape evolves towards distributed architectures such as Internet of Things (IoT), enterprises are moving away from traditional perimeter based security models toward so called “zero trust networking” (ZTN) models that treat both the intranet and Internet as equally untrustworthy. Such security models incorporate risk arising from dynamic and situational factors, such as device location and security risk level risk, into the access control decision. Researchers have developed a number of risk models such as RAdAC (Risk Adaptable Access Control) to handle dynamic contexts and these have been applied to medical and other scenarios. In this position paper we describe our ongoing work to apply RAdAC to ZTN. We develop a policy management framework, FURZE, to facilitate fuzzy risk evaluation that also defines how to adapt to dynamically changing contexts. We also consider how enterprise security situational awareness (SSA) - which describes the potential impact to an organisations mission based on the current threats and the relative importance of the information asset under threat - can be incorporated into a RAdAC scheme.en_US
dc.formatPDFen_US
dc.language.isoenen_US
dc.publisherAssociation for Computing Machineryen_US
dc.relation.ispartofICC '17: Proceedings of the Second International Conference on Internet of things, Data and Cloud Computingen_US
dc.rightsAttribution-NonCommercial-NoDerivs 3.0 Ireland*
dc.rights.urihttp://creativecommons.org/licenses/by-nc-nd/3.0/ie/*
dc.subjectRisk based access controlen_US
dc.subjectRAdACen_US
dc.subjectZero-trust networkingen_US
dc.subjectSecurity situational awarenessen_US
dc.titleSituational awareness based risk-adaptable access control in enterprise networks.en_US
dc.typeOtheren_US
dc.contributor.grantno70071en_US
dc.contributor.sponsorEuropean Union’s Horizon 2020 research and innovation programmeen_US
dc.description.peerreviewyesen_US
dc.identifier.conferenceICC '17: Proceedings of the Second International Conference on Internet of things, Data and Cloud Computing. Porto, Portugal. 16-17 June 2017.
dc.identifier.orcidhttps://orcid.org/0000-0002-8475-4074
dc.identifier.orcidhttps://orcid.org/0000-0001-5090-2756
dc.rights.accessOpen Accessen_US
dc.subject.departmentSoftware Research Institute AITen_US


Files in this item

Thumbnail
Thumbnail

This item appears in the following Collection(s)

Show simple item record

Attribution-NonCommercial-NoDerivs 3.0 Ireland
Except where otherwise noted, this item's license is described as Attribution-NonCommercial-NoDerivs 3.0 Ireland