Semantically Rich, Context-Aware, Attribute based Access Control Model for Cloud Systems

dc.contributor.advisorJoshi, Anupam
dc.contributor.authorRathod, Vishal
dc.contributor.departmentComputer Science and Electrical Engineering
dc.contributor.programComputer Science
dc.date.accessioned2021-01-29T18:12:39Z
dc.date.available2021-01-29T18:12:39Z
dc.date.issued2018-01-01
dc.description.abstractResource access control is an important research topic in cloud systems security. Much of the work has been focused on context-sensitive access control and rule representation. In an open source cloud computing platform such as OpenStack, operators use Role-Based Access Control (RBAC) model to grant user-access to cloud resources. However, these user level role-based access control technique fails to include a comprehensive user context. A situational aware framework will provide hardened access security by bringing in users context in such cloud systems. In this work, we propose a semantically rich context-sensitive access control system for OpenStack by incorporating the user's current context attributes like location, time, etc. We integrate our own knowledge graph dependent attribute-based policy system with OpenStack policy engine to demonstrate our approach. In a proof-of-concept implementation, we integrate a knowledge graph with our own access control system to express and enforce the contextual-situation policies in OpenStack, while keeping OpenStack's current RBAC architecture in place. The proposed system provides enhanced, flexible access control while minimizing the overhead of altering the existing access control framework. We present use cases to highlight the benefits of our system and show enforcement results. The study also investigates the flexibility of integrating different policy frameworks in Open-Stack in order to enhance the access control.
dc.formatapplication:pdf
dc.genretheses
dc.identifierdoi:10.13016/m2thpb-xlts
dc.identifier.other11907
dc.identifier.urihttp://hdl.handle.net/11603/20732
dc.languageen
dc.relation.isAvailableAtThe University of Maryland, Baltimore County (UMBC)
dc.relation.ispartofUMBC Computer Science and Electrical Engineering Department Collection
dc.relation.ispartofUMBC Theses and Dissertations Collection
dc.relation.ispartofUMBC Graduate School Collection
dc.relation.ispartofUMBC Student Collection
dc.sourceOriginal File Name: Rathod_umbc_0434M_11907.pdf
dc.subjectAccess Control
dc.subjectContextual Attributes
dc.subjectCybersecurity
dc.subjectKnowledge Graphs
dc.subjectOpenStack
dc.titleSemantically Rich, Context-Aware, Attribute based Access Control Model for Cloud Systems
dc.typeText
dcterms.accessRightsDistribution Rights granted to UMBC by the author.
dcterms.accessRightsAccess limited to the UMBC community. Item may possibly be obtained via Interlibrary Loan thorugh a local library, pending author/copyright holder's permission.
dcterms.accessRightsThis item is likely protected under Title 17 of the U.S. Copyright Law. Unless on a Creative Commons license, for uses protected by Copyright Law, contact the copyright holder or the author.

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Rathod_umbc_0434M_11907.pdf
Size:
1.04 MB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
RathodVSemantically_Open.pdf
Size:
43.88 KB
Format:
Adobe Portable Document Format
Description: