Adaptive Access Control Policies for IoT Deployments
Ashraf Alkhresheh, Khalid Elgazzar, Hossam S. Hassanein · 2020
In the era of the Internet of Things (IoT), it has become possible for a set of smart devices to collaborate autonomously and communicate seamlessly to achieve complex tasks that require a high degree of intelligence. Unlike traditional internet devices, a compromised IoT device can cause real-world damages. The severity of these damages increases dangerously in sensitive contexts especially when these devices are controlled by system insiders. Detecting abnormal access behaviors in such environments is quite challenging, due to frequent changes in the access contexts under which the IoT device can be accessed. In this paper, we propose an adaptive access control policy framework that dynamically refines the system access policies in response to changes in the device-to-device access behavior. We apply supervised machine learning to model and classify the device access behavior based on a real-life data set. We provide a use case scenario of a door locking system to validate our work. Results show that our framework provides improved security, dynamic adaptability and sufficient scalability to the target application domain.