One of the most important components in information systems security is the Access Control policy. In order to ensure the best Access Control policy, it is mandatory to proceed to a modeling phase that respects a set of indications and criteria of a predefined model. There exists several Access Control models, each with a specific contribution. This paper exposes the results found through a SWOT analysis on the well-known models, and presents the advantages and drawbacks of each model. Then, a comparative table between these models is elaborated, in order to get an overview on the types of problems encountered in Access Control and discover the common vulnerabilities between its models. The discovering of the covert channels is among the main results of this study.
목차
Abstract 1. Introduction 2. The DAC Model (Discretionary Access Control) 2.1. Introduction 2.2. The Lampson Model 2.3. The HRU Model 2.4. Problems Raised from DAC Model 3. The MAC model (Mandatory Access Control) 3.1. Introduction 3.2. The Bell-LaPadula Model (BLP) 3.3. The Biba Model 3.4. Problems Raised from MAC Model 4. The RBAC model (Role-Based Access Control) 4.1. Introduction 4.2. The RBAC0 Model (Core RBAC) 4.3. The RBAC1 model (The Hierarchy Role) 4.4. The RBAC2 model (The Constraints) 4.5. The RBAC3 Model 4.6. Problems Raised from RBAC Model 5. SWOT Analysis of Access Control Models 6. Conclusion References
키워드
Securityaccess controlpolicySWOT analysismodelinformation system
저자
Ennahbaoui Mohammed [ The laboratory of Mathematics, Computer science and Applications (LabMIA) Faculty of Science, University of Mohammed V-Agdal, Rabat, Morocco ]
El Hajji Said [ The laboratory of Mathematics, Computer science and Applications (LabMIA) Faculty of Science, University of Mohammed V-Agdal, Rabat, Morocco ]
보안공학연구지원센터(IJSIA) [Science & Engineering Research Support Center, Republic of Korea(IJSIA)]
설립연도
2006
분야
공학>컴퓨터학
소개
1. 보안공학에 대한 각종 조사 및 연구
2. 보안공학에 대한 응용기술 연구 및 발표
3. 보안공학에 관한 각종 학술 발표회 및 전시회 개최
4. 보안공학 기술의 상호 협조 및 정보교환
5. 보안공학에 관한 표준화 사업 및 규격의 제정
6. 보안공학에 관한 산학연 협동의 증진
7. 국제적 학술 교류 및 기술 협력
8. 보안공학에 관한 논문지 발간
9. 기타 본 회 목적 달성에 필요한 사업
간행물
간행물명
International Journal of Security and Its Applications
간기
격월간
pISSN
1738-9976
수록기간
2008~2016
등재여부
SCOPUS
십진분류
KDC 505DDC 605
이 권호 내 다른 논문 / International Journal of Security and Its Applications Vol.8 No.3