2009
DOI: 10.1016/j.ijcip.2009.08.005
|View full text |Cite
|
Sign up to set email alerts
|

PolyOrBAC: A security framework for Critical Infrastructures

Abstract: Due to physical and logical vulnerabilities, a critical infrastructure (CI) can encounter failures of various degrees of severity, and since there are many interdependencies between CIs, simple failures can have dramatic consequences on the users. In this paper, we mainly focus on malicious threats that might affect the information and communciation system that controls the Critical Infrastructure, i.e., the Critical Information Infrastructure (CII). To address the security challenges that are specific of CIIs… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
20
0
1

Year Published

2011
2011
2018
2018

Publication Types

Select...
4
4
1

Relationship

0
9

Authors

Journals

citations
Cited by 45 publications
(21 citation statements)
references
References 27 publications
0
20
0
1
Order By: Relevance
“…However, one of the big drawbacks of this model, especially when talking about IoT environments, is that it is based on a totally centralized architecture and does not provide or support the distribution, collaboration and interoperability requirements. That said, several works have done in order to extend OrBAC to overcome these limitation: PolyOrBAC [27] deals with this problem by using the OrBAC model to manage the internal policies of each organization, but to ensure the collaboration aspect between organizations, web services technology was. Nevertheless, such technologies that PolyOrBAC uses (e.g.…”
Section: Organization Based Access Control (Orbac)mentioning
confidence: 99%
“…However, one of the big drawbacks of this model, especially when talking about IoT environments, is that it is based on a totally centralized architecture and does not provide or support the distribution, collaboration and interoperability requirements. That said, several works have done in order to extend OrBAC to overcome these limitation: PolyOrBAC [27] deals with this problem by using the OrBAC model to manage the internal policies of each organization, but to ensure the collaboration aspect between organizations, web services technology was. Nevertheless, such technologies that PolyOrBAC uses (e.g.…”
Section: Organization Based Access Control (Orbac)mentioning
confidence: 99%
“…Other solutions can be integrated to increase the security level discussed in [58]. One consists of establishing a collaborative access control framework called PolyOrBAC.…”
Section: The Proposal In Multi-cloudsmentioning
confidence: 99%
“…The main concepts introduced by OrBAC are the following: (1) activity, regrouping actions having common properties; (2) view, several objects having the same properties on which the same rules are applied; and (3) context, a concept dening the circumstances in which some security rules can be applied. The context allows the denition of specic security requirements directly at the OrBAC level.…”
Section: The Orbac Modelmentioning
confidence: 99%
“…The concept of organization in OrBAC provides means to better analyze interoperability and specication of hierarchies which, in turn, leads to a exible specication of collaborative work and information ow between dierent organizations (e.g., companies and institutions). The OrBAC formalism and the expressiveness of general-purpose ontologies can be combined in order of guaranteeing organization interoperability and collaboration [11,2]. Negative authorizations are also allowed in OrBAC, in order to specify complex policies.…”
Section: Open Problems and Limitationsmentioning
confidence: 99%