Fuzzy Logic with Expert Judgment to Implement an Adaptive Risk-Based Access Control Model for IoT

被引:0
|
作者
Hany F. Atlam
Robert J. Walters
Gary B. Wills
Joshua Daniel
机构
[1] University of Southampton,Electronic and Computer Science Department
[2] Menoufia University,Computer Science and Engineering Department, Faculty of Electronic Engineering
[3] Security Futures Practice,undefined
[4] BT Research & Innovation,undefined
来源
关键词
Security risk; Internet of Things; Adaptive access control; Context; Fuzzy logic; Expert judgment;
D O I
暂无
中图分类号
学科分类号
摘要
The Internet of Things (IoT) is becoming the future of the Internet with a large number of connected devices that are predicted to reach about 50 billion by 2020. With proliferation of IoT devices and need to increase information sharing in IoT applications, risk-based access control model has become the best candidate for both academic and commercial organizations to address access control issues. This model carries out a security risk analysis on the access request by using IoT contextual information to provide access decisions dynamically. This model solves challenges related to flexibility and scalability of the IoT system. Therefore, we propose an adaptive risk-based access control model for the IoT. This model uses real-time contextual information associated with the requesting user to calculate the security risk regarding each access request. It uses user attributes while making the access request, action severity, resource sensitivity and user risk history as inputs to analyze and calculate the risk value to determine the access decision. To detect abnormal and malicious actions, smart contracts are used to track and monitor user activities during the access session to detect and prevent potential security violations. In addition, as the risk estimation process is the essential stage to build a risk-based model, this paper provides a discussion of common risk estimation methods and then proposes the fuzzy inference system with expert judgment as to be the optimal approach to handle risk estimation process of the proposed risk-based model in the IoT system.
引用
收藏
页码:2545 / 2557
页数:12
相关论文
共 50 条
  • [31] Control Design for Risk-Based Signal Temporal Logic Specifications
    Safaoui, Sleiman
    Lindemann, Lars
    Dimarogonas, Dimos, V
    Shames, Iman
    Summers, Tyler H.
    IEEE CONTROL SYSTEMS LETTERS, 2020, 4 (04): : 1000 - 1005
  • [32] A framework and risk assessment approaches for risk-based access control in the cloud
    dos Santos, Daniel Ricardo
    Marinho, Roberto
    Schmitt, Gustavo Roecker
    Westphall, Carla Merkle
    Westphall, Carlos Becker
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2016, 74 : 86 - 97
  • [33] Multiple model tracking based on adaptive fuzzy logic
    College of Automation Engineering, Nanjing University of Aeronautics and Astronautics, Nanjing 210016, China
    Guangxue Jingmi Gongcheng, 2009, 4 (867-873):
  • [34] Indirect Adaptive Model Predictive Control Supervised by Fuzzy Logic
    Mamboundou, Jerry
    Langlois, Nicolas
    IEEE INTERNATIONAL CONFERENCE ON FUZZY SYSTEMS (FUZZ 2011), 2011, : 2979 - 2986
  • [35] RISK-BASED DECISION MAKING FOR PUBLIC KEY INFRASTRUCTURES USING FUZZY LOGIC
    Ganan, Carlos
    Munoz, Jose L.
    Esparza, Oscar
    Mata-Diaz, Jorge
    Alins, Juanjo
    INTERNATIONAL JOURNAL OF INNOVATIVE COMPUTING INFORMATION AND CONTROL, 2012, 8 (11): : 7925 - 7942
  • [36] An Enhanced CoAP Scheme Using Fuzzy Logic With Adaptive Timeout for IoT Congestion Control
    Aimtongkham, Phet
    Horkaew, Paramate
    So-In, Chakchai
    IEEE ACCESS, 2021, 9 : 58967 - 58981
  • [37] A Dynamic Risk-based Access Control Architecture for Cloud Computing
    dos Santos, Daniel Ricardo
    Westphall, Carla Merkle
    Westphall, Carlos Becker
    2014 IEEE NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (NOMS), 2014,
  • [38] Dynamic risk-based decision methods for access control systems
    Shaikh, Riaz Ahmed
    Adi, Kamel
    Logrippo, Luigi
    COMPUTERS & SECURITY, 2012, 31 (04) : 447 - 464
  • [39] An Adaptive Risk-Based Access Control System Using Risk Factor for e-Services (ARBAC-RF)
    Ramtohul, Avinash
    PROCEEDINGS OF THE 16TH EUROPEAN CONFERENCE ON E-GOVERNMENT (ECEG 2016), 2016, : 291 - 301
  • [40] IoT Smart Devices Risk Assessment Model Using Fuzzy Logic and PSO
    Mashaleh, Ashraf S.
    Ibrahim, Noor Farizah Binti
    Alauthman, Mohammad
    Almseidin, Mohammad
    Gawanmeh, Amjad
    CMC-COMPUTERS MATERIALS & CONTINUA, 2024, 78 (02): : 2245 - 2267