An Architecture of Security Enhanced Access Control System to Prevent Leak the Internal Information

Un-Ho Lee, Jung-Ho Eom · Advanced science and technology letters · 2015

In this paper, we proposed an architecture of the security enhanced access control system to prevent leak the internal information in the business IT environment. Our proposed access control system added insider’s contexts information, the security level of document and the level of risk to strongly control insider access to database. Insider’s contexts information includes role, task, location, security level and so on. The security level of document means the sensitive level of document contents. The risk level of insider is assessed with the experience of security breaches. The proposed system was added context-aware module and user threat assessment module in existing access control system. So, the proposed system strongly controls the mode of operation (read, write, etc.) with the security level of internal information and insider, insider contexts and the risk level of insider.

Read the paper · More papers on PaperTik