by Tatyana Ryutov, Li Zhou, Clifford Neuman
In 10th ACM Symposium on Access Control Models and Technologies
http://gridsec.usc.edu/files/TR/atnac.pdf
Add To MetaCart
Abstract:
Electronic transactions regularly occur between business partners in separate security domains. Trust negotiation is an approach that provides an open authentication and access-control environment for such transactions, but it is vulnerable to malicious attacks leading to denial of service or leakage of sensitive information. This paper introduces an Adaptive Trust Negotiation and Access Control (ATNAC) framework to solve these problems. The framework combines two existing systems, TrustBuilder and GAA-API, to create a system with more flexibility and responsiveness to attack than either system currently provides. Categories and Subject Descriptors
Citations
|
110
|
Automated trust negotiation
– WINSBOROUGH, SEAMONS, et al.
- 2000
|
|
106
|
Access control meets public key infrastructure, or: Assigning roles to strangers
– Herzberg, Mass, et al.
- 2000
|
|
75
|
SD3: A trust management system with certified evaluation
– Jim
- 2001
|
|
60
|
RT: A role-based trust-management framework
– Li, Mitchell
- 2003
|
|
56
|
Towards practical automated trust negotiation
– WINSBOROUGH, LI
|
|
44
|
Negotiating trust on the web
– WINSLETT, YU, et al.
- 2002
|
|
41
|
Cassandra: Distributed access control policies with tunable expressiveness
– BECKER, SEWELL
|
|
28
|
RFC 1510: The Kerberos network authentication service (V5
– Kohl, Neuman
- 1993
|
|
27
|
A unified framework for regulating access and information release on the web
– Bonatti, Samarati
- 2002
|
|
22
|
A.C.: Trust-X : A peer-to-peer framework for trust establishment
– Bertino, Ferrari, et al.
- 2004
|
|
19
|
PeerTrust: automated trust negotiation for peers on the semantic web
– Nejdl, Olmedilla, et al.
- 2004
|
|
14
|
Integrated access control and intrusion detection for web servers
– Ryutov, Neuman, et al.
- 2003
|
|
14
|
Model-driven trust negotiation for web services
– Skogsrud, Benatallah, et al.
- 2003
|
|
13
|
The Specification and Enforcement of Advanced Security Policies
– Ryutov, Neuman
- 2002
|
|
5
|
Dynamic Authorization and Intrusion Response in Distributed Systems
– Ryutov, Neuman, et al.
- 2003
|
|
5
|
Dalit Naor, and Yiftach Ravid, Access control meets public key infrastructure, or: Assigning roles to strangers
– Herzberg, Mass, et al.
- 2000
|
|
2
|
Anna Cinzia Squicciarini, Trust-X: A Peer-to-Peer Framework for Trust Establishment
– Bertino, Ferrari
- 2004
|
|
1
|
Pierangela Samarati, A Unified Framework for Regulating Access and Information Release on the Web
– Bonatti
|
|
1
|
Boualem Benatallah, and Fabio Casati, Model-driven trust negotiation for Web services
– Skogsrud
- 2003
|