{"title":"网络隔离系统的混合RBAC-PBAC访问控制模型","authors":"Haiyan Wu, Chengxiang Tan, Haihang Wang","doi":"10.1109/WKDD.2008.120","DOIUrl":null,"url":null,"abstract":"Network isolation system integrates various technologies to achieve its high-security performance and access control is an indispensable one among them. In order to control and manage accesses to all the services provided by network isolation system, we need to establish an efficient access control model and make a set of fine-grained rules for the model. In this paper, we analyze service access control requirements in network isolation system firstly. And, according to the special running environment, we propose a hybrid service access control model based on RBAC (Role- based Access Control) and PBAC (Police-based Access Control). Then, we research rules making and realization method of the proposed model. In the end, we realize the hybrid model and its configuration.","PeriodicalId":101656,"journal":{"name":"First International Workshop on Knowledge Discovery and Data Mining (WKDD 2008)","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2008-01-23","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":"{\"title\":\"A Hybrid RBAC-PBAC Access Control Model for Network Isolation System\",\"authors\":\"Haiyan Wu, Chengxiang Tan, Haihang Wang\",\"doi\":\"10.1109/WKDD.2008.120\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Network isolation system integrates various technologies to achieve its high-security performance and access control is an indispensable one among them. In order to control and manage accesses to all the services provided by network isolation system, we need to establish an efficient access control model and make a set of fine-grained rules for the model. In this paper, we analyze service access control requirements in network isolation system firstly. And, according to the special running environment, we propose a hybrid service access control model based on RBAC (Role- based Access Control) and PBAC (Police-based Access Control). Then, we research rules making and realization method of the proposed model. In the end, we realize the hybrid model and its configuration.\",\"PeriodicalId\":101656,\"journal\":{\"name\":\"First International Workshop on Knowledge Discovery and Data Mining (WKDD 2008)\",\"volume\":\"1 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2008-01-23\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"2\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"First International Workshop on Knowledge Discovery and Data Mining (WKDD 2008)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/WKDD.2008.120\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"First International Workshop on Knowledge Discovery and Data Mining (WKDD 2008)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/WKDD.2008.120","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2
摘要
网络隔离系统集成了多种技术来实现其高安全性能,访问控制是其中不可或缺的一项技术。为了控制和管理对网络隔离系统所提供的所有服务的访问,我们需要建立一个高效的访问控制模型,并为该模型制定一套细粒度的规则。本文首先分析了网络隔离系统中的业务访问控制需求。并根据特殊的运行环境,提出了一种基于RBAC (Role- based access control)和PBAC (policy -based access control)的混合服务访问控制模型。然后,研究了该模型的规则制定和实现方法。最后,实现了混合模型及其配置。
A Hybrid RBAC-PBAC Access Control Model for Network Isolation System
Network isolation system integrates various technologies to achieve its high-security performance and access control is an indispensable one among them. In order to control and manage accesses to all the services provided by network isolation system, we need to establish an efficient access control model and make a set of fine-grained rules for the model. In this paper, we analyze service access control requirements in network isolation system firstly. And, according to the special running environment, we propose a hybrid service access control model based on RBAC (Role- based Access Control) and PBAC (Police-based Access Control). Then, we research rules making and realization method of the proposed model. In the end, we realize the hybrid model and its configuration.