Toward Information Sharing: Benefit And Risk Access Control (BARAC)

  • Authors:
  • Lei Zhang;Alexander Brodsky;Sushil Jajodia

  • Affiliations:
  • George Mason University, USA;George Mason University, USA;The MITRE Corporation, USA

  • Venue:
  • POLICY '06 Proceedings of the Seventh IEEE International Workshop on Policies for Distributed Systems and Networks
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper describes an access control model, called BARAC, that is based on balancing risks of information disclosure with benefits of information sharing. The model configuration associates risk and benefit vectors with every read and update transaction. An allowed transactions graph captures allowed transactions and flow paths that can be used to carry out the transactions. The total system is required to be profitable, in that the total system benefit must overweigh the total system risk; and the allowed transaction graph is required to be optimal, in that its profit cannot be improved by adding transactions or removing transactions. Both the system configuration and the allowed transaction graph can be dynamically modified, while preserving the required properties. The dynamic modifications are done in the scope of hierarchies of tasks and responsible parties, that control the task structure and risk budget allocation to tasks.