Fuzzy Logic with Expert Judgment to Implement an Adaptive Risk-Based Access Control Model for IoT

被引:0
|
作者
Hany F. Atlam
Robert J. Walters
Gary B. Wills
Joshua Daniel
机构
[1] University of Southampton,Electronic and Computer Science Department
[2] Menoufia University,Computer Science and Engineering Department, Faculty of Electronic Engineering
[3] Security Futures Practice,undefined
[4] BT Research & Innovation,undefined
来源
关键词
Security risk; Internet of Things; Adaptive access control; Context; Fuzzy logic; Expert judgment;
D O I
暂无
中图分类号
学科分类号
摘要
The Internet of Things (IoT) is becoming the future of the Internet with a large number of connected devices that are predicted to reach about 50 billion by 2020. With proliferation of IoT devices and need to increase information sharing in IoT applications, risk-based access control model has become the best candidate for both academic and commercial organizations to address access control issues. This model carries out a security risk analysis on the access request by using IoT contextual information to provide access decisions dynamically. This model solves challenges related to flexibility and scalability of the IoT system. Therefore, we propose an adaptive risk-based access control model for the IoT. This model uses real-time contextual information associated with the requesting user to calculate the security risk regarding each access request. It uses user attributes while making the access request, action severity, resource sensitivity and user risk history as inputs to analyze and calculate the risk value to determine the access decision. To detect abnormal and malicious actions, smart contracts are used to track and monitor user activities during the access session to detect and prevent potential security violations. In addition, as the risk estimation process is the essential stage to build a risk-based model, this paper provides a discussion of common risk estimation methods and then proposes the fuzzy inference system with expert judgment as to be the optimal approach to handle risk estimation process of the proposed risk-based model in the IoT system.
引用
收藏
页码:2545 / 2557
页数:12
相关论文
共 50 条
  • [1] Fuzzy Logic with Expert Judgment to Implement an Adaptive Risk-Based Access Control Model for IoT
    Atlam, Hany F.
    Walters, Robert J.
    Wills, Gary B.
    Daniel, Joshua
    MOBILE NETWORKS & APPLICATIONS, 2021, 26 (06): : 2545 - 2557
  • [2] An efficient security risk estimation technique for Risk-based access control model for IoT
    Atlam, Hany F.
    Wills, Gary B.
    INTERNET OF THINGS, 2019, 6
  • [3] Developing an adaptive Risk-based access control model for the Internet of Things
    Atlam, Hany F.
    Alenezi, Ahmed
    Walters, Robert J.
    Wills, Gary B.
    Daniel, Joshua
    2017 IEEE INTERNATIONAL CONFERENCE ON INTERNET OF THINGS (ITHINGS) AND IEEE GREEN COMPUTING AND COMMUNICATIONS (GREENCOM) AND IEEE CYBER, PHYSICAL AND SOCIAL COMPUTING (CPSCOM) AND IEEE SMART DATA (SMARTDATA), 2017, : 655 - 661
  • [4] Fuzzy logic and risk-based soil interpretations
    Mays, MD
    Bogardi, I
    Bardossy, A
    GEODERMA, 1997, 77 (2-4) : 299 - 315
  • [5] A Fuzzy Modeling Approach for Risk-based Access Control in eHealth Cloud
    Li, Juan
    Bai, Yan
    Zaman, Nazia
    2013 12TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2013), 2013, : 17 - 23
  • [6] Efficient NFS Model for Risk Estimation in a Risk-Based Access Control Model
    Atlam, Hany F.
    Azad, Muhammad Ajmal
    Fadhel, Nawfal F.
    SENSORS, 2022, 22 (05)
  • [7] A Dynamic Risk-based Access Control Model for Cloud Computing
    Chen, Aiguo
    Xing, Hanwen
    She, Kun
    Duan, Guiduo
    PROCEEDINGS OF 2016 IEEE INTERNATIONAL CONFERENCES ON BIG DATA AND CLOUD COMPUTING (BDCLOUD 2016) SOCIAL COMPUTING AND NETWORKING (SOCIALCOM 2016) SUSTAINABLE COMPUTING AND COMMUNICATIONS (SUSTAINCOM 2016) (BDCLOUD-SOCIALCOM-SUSTAINCOM 2016), 2016, : 579 - 584
  • [8] Risk-Based Access Control Model: A Systematic Literature Review
    Atlam, Hany F.
    Azad, Muhammad Ajmal
    Alassafi, Madini O.
    Alshdadi, Abdulrahman A.
    Alenezi, Ahmed
    FUTURE INTERNET, 2020, 12 (06):
  • [9] A fuzzy logic based multiple reference model adaptive control
    Kamalasadan, S
    Ghandakly, AA
    Al-Olimat, K
    COMPUTER APPLICATIONS IN INDUSTRY AND ENGINEERING, 2003, : 58 - 61
  • [10] ANFIS for risk estimation in risk-based access control model for smart homes
    Hany F. Atlam
    Gary B. Wills
    Multimedia Tools and Applications, 2023, 82 : 18269 - 18298