期刊文献+

云平台访问控制自适应风险评估指标权重分配方法 被引量:8

Adaptive weight allocation method of risk assessment index for access control of cloud platform
下载PDF
导出
摘要 针对云平台风险访问控制模型中风险评估指标权重主观设定且固定的问题,提出自适应风险评估指标权重分配方法。首先,通过带约束的多元线性回归设计自适应风险评估指标权重分配模型;然后,提出并优化配方回归算法求解相应权重;最后,构建带有自适应权重分配的风险值量化公式,动态计算访问请求的风险值。实验结果表明,该方法与动态风险访问控制(DRAC)模型、基于系统安全风险的访问控制模型相比,在训练集数量级相同的条件下,其风险值的准确率和灵敏度平均提升了2.8%和18.5%、1.7%和18.7%。该方法与DRAC模型、基于动态属性的风险感知访问控制(DA-RAAC)模型以及基于系统安全风险的访问控制模型相比,在访问请求数量相同的条件下,响应时间平均缩短了9.2%、34.6%和96.6%。所提方法在大并发用户数情况下所得风险值有较高的准确率和灵敏度,且响应时间更短,更适用于云环境。 Aiming at the subjective and fixed setting problems of risk assessment index weight in risk access control model of cloud platform, an adaptive weight allocation method of risk assessment index was proposed. Firstly, the the adaptive weight allocation model of risk assessment index was designed through a multivariate linear regression with constraints.Secondly, the programming regression algorithm was proposed and optimized to solve the corresponding weight. Finally, the quantitative formula of risk value with adaptive weight allocation was constructed to calculate the risk value of access request dynamically. The experimental results show that, compared with the Dynamic Risk-based Access Control(DRAC) model and the access control model based on system security risk, the accuracy and sensitivity of risk value of the proposed method are averagely increased by 2. 8% and 18. 5%, 1. 7% and 18. 7% with the same order of magnitude training set. Compared with the DRAC model, Dynamic Attribute-based Risk Aware Access Control(DA-RAAC) model and the access control model based on system security risk, the response time of the proposed method is averagely shortened by 9. 2%, 34. 6% and 96. 6%with the same number of access requests. The proposed method has higher accuracy and sensitivity in the risk value of large concurrent users, and its response time is shorter, which is more suitable for cloud environment.
作者 杨宏宇 宁宇光 YANG Hongyu , NING Yuguang(College of Computer Science and Technology, Civil Aviation University of China, Tianjin 300300, Chin)
出处 《计算机应用》 CSCD 北大核心 2018年第6期1614-1619,共6页 journal of Computer Applications
基金 中国民航科技基金资助项目(MHRD201205)~~
关键词 访问控制 指标权重 配方回归 自适应 云平台 access control index weight programming regression adaptability cloud platform
  • 相关文献

参考文献4

二级参考文献38

  • 1张义荣,鲜明,王国玉.一种基于网络熵的计算机网络攻击效果定量评估方法[J].通信学报,2004,25(11):158-165. 被引量:55
  • 2王美乂,张凤鸣,刘智.模糊信息的熵权多属性决策方案评估方法[J].系统工程与电子技术,2006,28(10):1523-1525. 被引量:37
  • 3林闯,雷蕾.下一代互联网体系结构研究[J].计算机学报,2007,30(5):693-711. 被引量:64
  • 4吴晓平,付钰.信息系统安全风险评估理论与方法[M].北京:科学出版社,2010.
  • 5达新宇,陈树新,王瑜,等.通信原理教程(第二版)[M].北京:北京邮电大学出版社,2009:318320.
  • 6FUNG C, ZHANG J, AIB I, et al. Trust management and admission control for host-based collaborative intrusion detection[J]. Journal of Network and Systems Management, 2011, 19(2):257-277.
  • 7TAJEDDINE A, KAYSSI A, CHEHAB A, 'et al. Fuzzy reputation- based trust model[J]. Applied Soft Computing, 2011, 11(1):345-355.
  • 8CK)VINDAN K. Trust computations and trust dynamics in mobile ad hoc networks: a survey[J]. Communications Surveys & Tutorials, 2011, 14(2):279-298.
  • 9RAYA M, PAPADIMITRATOS P, GLIGOR V D, et al. On data-centric trust establishment in ephemeral ad hoc networks[A]. INFOCOM[C]. 2008.13-18.
  • 10XI Z Y, CHEN H, WANG X Z, et al. Evaluation model for computer network information security based on analytic hierarchy process[A]. Intelligent Information Technology Applicaffon[C]. 2009.

共引文献302

同被引文献92

引证文献8

二级引证文献15

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部