TY - GEN
T1 - An Evolutionary Risk-based Access Control Framework for Enterprise File Systems
AU - Cha, Shi Cho
AU - Hsuan, Yi Hsuan
AU - Yeh, Kuo Hui
AU - Ishihara, Takeshi
AU - Yoshihiro, Ohba
AU - Chen, Wei Nin
N1 - Publisher Copyright:
© 2022 IEEE.
PY - 2022
Y1 - 2022
N2 - To enhance access control mechanisms, organizations need to monitor access requests issued from devices. There-fore, organizations can evaluate the trustworthiness or risks of the devices based on collected requests to adapt the access privileges. However, existing schemes usually do not address organizational authorization processes and may not be suitable for enterprise file systems. In light of this, this study proposes an Evolutionary Risk Adaptive Access Control (ERAAC) Framework for enterprise file systems. The proposed framework provides an extensible architecture for an organization to deploy different access control filters for different perspectives. An access control filter can filter out access requests based on access control policies. An organization can add a new access control filter without replacing its existing access control mechanism. In addition, the proposed framework enables organizations to define new risk labels for data entities, such as subjects and objects to be accessed, used in access control policies. The access control mechanism can adapt user privileges based on the risk labels. Even if organizations do not have enough data to generate risk labels, the organizations can set access control policies without risk labels. Therefore, the proposed framework enables organizations to progressively improve their access control mechanisms. To the best of our knowledge, the proposed framework is the first access control framework that can evolve with organizational maturity in risk management. This study also illustrates how the proposed framework satisfied the related tenets mentioned in NIST SP 800-207. Consequently, this study can hopefully contribute to helping an organization to implement zero trust architecture.
AB - To enhance access control mechanisms, organizations need to monitor access requests issued from devices. There-fore, organizations can evaluate the trustworthiness or risks of the devices based on collected requests to adapt the access privileges. However, existing schemes usually do not address organizational authorization processes and may not be suitable for enterprise file systems. In light of this, this study proposes an Evolutionary Risk Adaptive Access Control (ERAAC) Framework for enterprise file systems. The proposed framework provides an extensible architecture for an organization to deploy different access control filters for different perspectives. An access control filter can filter out access requests based on access control policies. An organization can add a new access control filter without replacing its existing access control mechanism. In addition, the proposed framework enables organizations to define new risk labels for data entities, such as subjects and objects to be accessed, used in access control policies. The access control mechanism can adapt user privileges based on the risk labels. Even if organizations do not have enough data to generate risk labels, the organizations can set access control policies without risk labels. Therefore, the proposed framework enables organizations to progressively improve their access control mechanisms. To the best of our knowledge, the proposed framework is the first access control framework that can evolve with organizational maturity in risk management. This study also illustrates how the proposed framework satisfied the related tenets mentioned in NIST SP 800-207. Consequently, this study can hopefully contribute to helping an organization to implement zero trust architecture.
KW - ZTA
KW - access control
KW - risk-adaptive
KW - security risk
UR - http://www.scopus.com/inward/record.url?scp=85164186731&partnerID=8YFLogxK
U2 - 10.1109/WF-IoT54382.2022.10152041
DO - 10.1109/WF-IoT54382.2022.10152041
M3 - Conference contribution
AN - SCOPUS:85164186731
T3 - 2022 IEEE 8th World Forum on Internet of Things, WF-IoT 2022
BT - 2022 IEEE 8th World Forum on Internet of Things, WF-IoT 2022
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 8th IEEE World Forum on Internet of Things, WF-IoT 2022
Y2 - 26 October 2022 through 11 November 2022
ER -