Advanced analysis of the integrity of access control policies : the specific case of databases

المؤلفون المشاركون

Bouhoula, Adel
al-Juaydi, Fawzi
Ayyashi, Fatin

المصدر

The International Arab Journal of Information Technology

العدد

المجلد 17، العدد 5 (30 سبتمبر/أيلول 2020)، ص ص. 808-815، 8ص.

الناشر

جامعة الزرقاء عمادة البحث العلمي

تاريخ النشر

2020-09-30

دولة النشر

الأردن

عدد الصفحات

8

التخصصات الرئيسية

تكنولوجيا المعلومات وعلم الحاسوب

الملخص EN

Databases are considered as one of the most compromised assets according to 2014-2016 Verizon Data Breach Reports.

The reason is that databases are at the heart of Information Systems (IS) and store confidential business or private records.

Ensuring the integrity of sensitive records is highly required and even vital in critical systems (e-health, clouds, e government, big data, e-commerce, etc.,).

The access control is a key mechanism for ensuring the integrity and preserving the privacy in large scale and critical infrastructures.

Nonetheless, excessive, unused and abused access privileges are identified as most critical threats in the top ten database security threats according to 2013-2015 Imperva Application Defense Center reports.

To address this issue, we focus in this paper on the analysis of the integrity of access control policies within relational databases.

We propose a rigorous and complete solution to help security architects verifying the correspondence between the security planning and its concrete implementation.

We define a formal framework for detecting non-compliance anomalies in concrete Role Based Access Control (RBAC) policies.

We rely on an example to illustrate the relevance of our contribution.

نمط استشهاد جمعية علماء النفس الأمريكية (APA)

al-Juaydi, Fawzi& Ayyashi, Fatin& Bouhoula, Adel. 2020. Advanced analysis of the integrity of access control policies : the specific case of databases. The International Arab Journal of Information Technology،Vol. 17, no. 5, pp.808-815.
https://search.emarefa.net/detail/BIM-1439793

نمط استشهاد الجمعية الأمريكية للغات الحديثة (MLA)

Bouhoula, Adel…[et al.]. Advanced analysis of the integrity of access control policies : the specific case of databases. The International Arab Journal of Information Technology Vol. 17, no. 5 (Sep. 2020), pp.808-815.
https://search.emarefa.net/detail/BIM-1439793

نمط استشهاد الجمعية الطبية الأمريكية (AMA)

al-Juaydi, Fawzi& Ayyashi, Fatin& Bouhoula, Adel. Advanced analysis of the integrity of access control policies : the specific case of databases. The International Arab Journal of Information Technology. 2020. Vol. 17, no. 5, pp.808-815.
https://search.emarefa.net/detail/BIM-1439793

نوع البيانات

مقالات

لغة النص

الإنجليزية

الملاحظات

Includes bibliographical references : p. 814

رقم السجل

BIM-1439793