Computer Security: Principles and Practice, 1/e



Download 7,14 Mb.
bet6/7
Sana10.11.2022
Hajmi7,14 Mb.
#862889
1   2   3   4   5   6   7
Bog'liq
04-AccessControl

Prerequisite Roles
    • Dictates that a user can only be assigned to a particular role if it is already assigned to some other specified role
    • E.g. can be used to structure the impl. of the least privilege concept

Attribute-based Access Control (ABAC)

  • ABAC is a logical access control model that controls access to objects by evaluating rules against the attributes of entities (subject and object), operations, and the environment relevant to a request.
  • Define authorizations that express conditions on properties of both the resource and the subject
    • E.g. consider a configuration in which each resource has an attribute that identifies the subject that created the resource.
    • Then, a single access rule can specify the ownership privilege for all the creators of every resource
  • Pros:
  • Cons:
    • Main obstacle to its adoption in real systems has been concern about the performance impact of evaluating predicates on both resource and user properties for each access.

Attribute-Based Access Control (ABAC)


Can define authorizations that express conditions on properties of both the resource and the subject
Strength is its flexibility and expressive power
Main obstacle to its adoption in real systems has been concern about the performance impact of evaluating predicates on both resource and user properties for each access
Web services have been pioneering technologies through the introduction of the eXtensible Access Control Markup Language (XAMCL)
There is considerable interest in applying the model to cloud services

ABAC Model: Attributes


Subject attributes
    • A subject is an active entity that causes information to flow among objects or changes the system state
    • Attributes define the identity and characteristics of the subject


Download 7,14 Mb.

Do'stlaringiz bilan baham:
1   2   3   4   5   6   7




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©www.hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish