CROct 26, 2017

Situational Awareness based Risk-Adapatable Access Control in Enterprise Networks

arXiv:1710.09696v121 citations
Originality Synthesis-oriented
AI Analysis

This work addresses the need for more adaptive security in enterprise networks moving to zero trust models, but it is incremental as it builds on existing risk-adaptable access control methods.

The paper tackles the problem of adapting access control to dynamic risk factors in zero trust enterprise networks by proposing a policy management framework called FURZE for fuzzy risk evaluation and incorporating security situational awareness into a risk-adaptable access control scheme, but it does not provide concrete results or numbers as it is a position paper on ongoing work.

As the computing landscape evolves towards distributed architectures such as Internet of Things (IoT),enterprises are moving away from traditional perimeter based security models toward so called zero trust networking (ZTN) models that treat both the intranet and Internet as equally untrustworthy. Such security models incorporate risk arising from dynamic and situational factors, such as device location and security risk level risk, into the access control decision. Researchers have developed a number of risk models such as RAdAC (Risk Adaptable Access Control) to handle dynamic contexts and these have been applied to medical and other scenarios. In this position paper we describe our ongoing work to apply RAdAC to ZTN. We develop a policy management framework, FURZE, to facilitate fuzzy risk evaluation that also defines how to adapt to dynamically changing contexts. We also consider how enterprise security situational awareness (SSA) - which describes the potential impact to an organisations mission based on the current threats and the relative importance of the information asset under threat - can be incorporated into a RAdAC scheme

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes