loading
Papers Papers/2022 Papers Papers/2022

Research.Publish.Connect.

Paper

Authors: Leonard Bradatsch ; Artur Hermann and Frank Kargl

Affiliation: Institute of Distributed Systems, Ulm University, Albert-Einstein-Allee 11, 89081 Ulm, Germany

Keyword(s): Access Control, Threat Analysis, Risk Assessment, Zero Trust Security.

Abstract: As enterprises increasingly adopt Zero Trust security, access control based on attributes is regaining attention as a core aspect of Zero Trust. Evaluating the accuracy of access decisions is a vital aspect of securing access control systems, typically involving threat analysis and risk assessment. A notable threat is attackers gaining illegitimate access by compromising the attributes checked by the access control policies. However, a systematic methodology for assessing attribute compromise risk is lacking. Knowing this risk aids in designing more accurate access control policies. This paper introduces a novel framework to address this gap, using modeled attackers and enterprises for risk assessment of attribute compromise. We also present a detailed case study featuring six attackers and two enterprises, demonstrating the framework’s practicality and providing insights into the security strength of fifteen common access control attributes. In the context of the case study, attribu tes such as Certificate Authentication , along with User Usage and Device Usage, which both reflect the coupling of users and devices, demonstrated high resilience against compromise attempts. (More)

CC BY-NC-ND 4.0

Sign In Guest: Register as new SciTePress user now for free.

Sign In SciTePress user: please login.

PDF ImageMy Papers

You are not signed in, therefore limits apply to your IP address 18.189.186.95

In the current month:
Recent papers: 100 available of 100 total
2+ years older papers: 200 available of 200 total

Paper citation in several formats:
Bradatsch, L., Hermann, A. and Kargl, F. (2024). Attribute Threat Analysis and Risk Assessment for ABAC and TBAC Systems. In Proceedings of the 21st International Conference on Security and Cryptography - SECRYPT; ISBN 978-989-758-709-2; ISSN 2184-7711, SciTePress, pages 26-39. DOI: 10.5220/0012715300003767

@conference{secrypt24,
author={Leonard Bradatsch and Artur Hermann and Frank Kargl},
title={Attribute Threat Analysis and Risk Assessment for ABAC and TBAC Systems},
booktitle={Proceedings of the 21st International Conference on Security and Cryptography - SECRYPT},
year={2024},
pages={26-39},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0012715300003767},
isbn={978-989-758-709-2},
issn={2184-7711},
}

TY - CONF

JO - Proceedings of the 21st International Conference on Security and Cryptography - SECRYPT
TI - Attribute Threat Analysis and Risk Assessment for ABAC and TBAC Systems
SN - 978-989-758-709-2
IS - 2184-7711
AU - Bradatsch, L.
AU - Hermann, A.
AU - Kargl, F.
PY - 2024
SP - 26
EP - 39
DO - 10.5220/0012715300003767
PB - SciTePress