Bailey, Christopher, de Lemos, Rogério (2020) Malicious Changeload for the Resilience Evaluation of Self-adaptive Authorisation Infrastructures. Future Generation Computer Systems, 113 . pp. 113-131. ISSN 0167-739X. (doi:10.1016/j.future.2020.06.045) (KAR id:81860)
|
PDF
Author's Accepted Manuscript
Language: English
This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.
|
|
|
Download this file (PDF/2MB) |
Preview |
| Request a format suitable for use with assistive technology e.g. a screenreader | |
| Official URL: https://doi.org/10.1016/j.future.2020.06.045 |
|
Abstract
Self-adaptive systems are able to modify their behaviour and/or structure in response to changes that occur to the system, its environment, or even its goals. In terms of authorisation infrastructures, self-adaptation has shown to be a promising solution for enforcing access control policies and subject access privileges when mitigating insider threat. This paper describes the resilience evaluation of a self-adaptive authorisation infrastructure by simulating a case study related to insider threats. As part of this evaluation, a malicious changeload has been formally defined in order to describe scenarios of abuse in access control. This malicious changeload was then used to stimulate self-adaptation within a federated authorisation infrastructure.
The evaluation confirmed the resilience of a self-adaptive authorisation infrastructure in handling abuse of access under repeatable conditions by consistently mitigating abuse under normal and high loads. The evaluation has also shown that self-adaptation had a minimal impact on the authorisation infrastructure, even when adapting authorisation policies while mitigating abuse of access.
| Item Type: | Article |
|---|---|
| DOI/Identification number: | 10.1016/j.future.2020.06.045 |
| Uncontrolled keywords: | self-protecting systems, authorisation infrastructures, changeload, insider threats, autonomic computing, access control |
| Subjects: |
Q Science > QA Mathematics (inc Computing science) > QA 76 Software, computer programming, Q Science > QA Mathematics (inc Computing science) > QA 76 Software, computer programming, > QA76.76 Computer software |
| Institutional Unit: | Schools > School of Computing |
| Former Institutional Unit: |
Divisions > Division of Computing, Engineering and Mathematical Sciences > School of Computing
|
| Depositing User: | Rogerio De Lemos |
| Date Deposited: | 25 Jun 2020 06:16 UTC |
| Last Modified: | 22 Jul 2025 09:02 UTC |
| Resource URI: | https://kar.kent.ac.uk/id/eprint/81860 (The current URI for this page, for reference purposes) |
- Link to SensusAccess
- Export to:
- RefWorks
- EPrints3 XML
- BibTeX
- CSV
- Depositors only (login required):

https://orcid.org/0000-0002-0281-6308
Altmetric
Altmetric