Log Content Extraction Engine Based on Ontology for the Purpose of a posteriori Access Control - Archive ouverte HAL Accéder directement au contenu
Article Dans Une Revue International Journal of Knowledge and Learning Année : 2014

Log Content Extraction Engine Based on Ontology for the Purpose of a posteriori Access Control

Résumé

In some complex information systems, users do not undergo untimely access controls. Generally, whenever they perform an action, this action is logged by the target system. Based on these log les, a security control called a posteriori access control is made afterwards. The logged data can be recorded in dierent formats (Syslog, W3C extend log, specic domain log standard like IHE-ATNA, etc.). An a posteriori security control framework requires a log ltering engine which extracts useful information regardless of the log format used. In this paper, we dene and enforce this extraction function by building an ontology model of logs. This logs ontology is queried to check the compliance of actions performed by the users of the considered system with its access control policy (violations, anomalies, fulllments, etc.). We show how the a posteriori security controls are made eective and how security decisions are made easier based on this extraction function.
Fichier non déposé

Dates et versions

hal-01219697 , version 1 (23-10-2015)

Identifiants

Citer

Hanieh Azkia, Nora Cuppens-Bouhlahia, Frédéric Cuppens, Gouenou Coatrieux. Log Content Extraction Engine Based on Ontology for the Purpose of a posteriori Access Control. International Journal of Knowledge and Learning, 2014, 9 (1-2), pp.23 - 42. ⟨10.1504/IJKL.2014.067149⟩. ⟨hal-01219697⟩
226 Consultations
0 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More