Incorporating Policy-Based Authorization Framework in Audit Rule Ontology for Continuous Process Auditing in Complex Distributed Systems

被引:0
|
作者
Subhani, Numanul [1 ]
Kent, Robert [1 ]
机构
[1] Univ Windsor, Sch Comp Sci, Windsor, ON N9B 3P4, Canada
关键词
Policy-based Authorization; Continuous Process Auditing; Audit Rule Ontology; Authorization and Access Control; Semantic Web; Risk-Adaptive Access Control (RAdAC);
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Complex distributed information systems that run their activities in the form of processes require continuous auditing of a process that invokes the action(s) specified in the policies and rules in a continuous manner. A shared vocabulary, or common ontology, used to defined the processes, and the audit rule ontology for processes or modules are integrated to form a hybrid ontology that supports the acquisition and evolution of ontologies. A methodology to construct a Common Ontology and an audit rule ontology by coupling to an expert system for Continuous Process Auditing (CPA) has been introduced recently. In this paper, we present a policy-based authorization methodology incorporating Audit Rule Ontology for CPA within distributed audit rule ontology. We also propose the use of probabilistic risk determination and evaluation of risk level, along with access history heuristics that define the adaptable access control policies before making policy decisions.
引用
收藏
页码:367 / 376
页数:10
相关论文
共 4 条
  • [1] Continuous Process Auditing (CPA): an Audit Rule Ontology based approach to Audit-as-a-Service
    Subhani, Numanul
    Kent, Robert D.
    2015 9TH ANNUAL IEEE INTERNATIONAL SYSTEMS CONFERENCE (SYSCON), 2015, : 832 - 838
  • [2] A DSL Framework for Policy-based Security of Distributed Systems
    Hamdi, Hedi
    Mosbah, Mohamed
    2009 THIRD IEEE INTERNATIONAL CONFERENCE ON SECURE SOFTWARE INTEGRATION AND RELIABILITY IMPROVEMENT, PROCEEDINGS, 2009, : 150 - 158
  • [3] A policy-based management framework for pervasive systems using axiomatized rule-actions
    Shankar, C
    Campbell, R
    Fourth IEEE International Symposium on Network Computing and Applications, Proceedings, 2005, : 255 - 258
  • [4] Issues in managing soft QoS requirements in distributed systems using a policy-based framework
    Lutfiyya, H
    Molenkamp, G
    Katchabaw, M
    Bauer, M
    POLICIES FOR DISTRIBUTED SYSTEMS AND NETWORKS, PROCEEDINGS, 2001, 1995 : 185 - 201