There are many web applications around us providing their services using web services. In order to prevent malicious users from accessing the web services is an important challenge now. Hence this proposed access control model provides the user an effective way to prevent the malicious user by calculating the trust value of every user based on their behaviours such as success rate, failure rate, frequent of access, transaction timeout etc., in the web application. This model also notices and precludes IP address spoofing, SQL injection to allow only the authorized users and access appropriate information. Prototype implementation and simulation results show the proposed model is the effective one when it is compared with existing models.