信息网络安全 ›› 2016, Vol. 16 ›› Issue (10): 34-39.doi: 10.3969/j.issn.1671-1122.2016.10.006

• • 上一篇    下一篇

一个基于用户网络行为的访问控制模型

刘畅(), 何泾沙   

  1. 北京工业大学软件学院,北京 100124
  • 收稿日期:2016-08-01 出版日期:2016-10-31 发布日期:2020-05-13
  • 作者简介:

    作者简介: 刘畅(1992—),女,北京,硕士研究生,主要研究方向为访问控制;何泾沙(1961—),男,陕西,教授,博士,主要研究方向为网络安全和云计算。

  • 基金资助:
    国家自然科学基金[61272500];国家高技术研究发展计划(国家863计划)[2015AA017204];北京市自然科学基金[4142008]

A Network Behavior-based Access Control Model

Chang LIU(), Jingsha HE   

  1. School of Software, Beijing University of Technology, Beijing 100124, China
  • Received:2016-08-01 Online:2016-10-31 Published:2020-05-13

摘要:

针对开放式网络环境中身份认证和行为认证分离这一问题,文章从用户网络行为的规律和特点出发,在传统身份认证的基础上,提出了基于用户行为认证的访问控制模型。文章明确了用户网络行为的定义,随后以用户浏览时间和访问路径作为数据源,将算法得出的计算值与阈值对照,结合时态信息和环境信息对用户行为建模,对用户行为进行验证。对于新用户,基于马尔科夫链对其行为进行检测,对于已存在的用户,根据数据源构建频繁访问有向树,并用均值方差算法对行为进行检测。该模型能够适应用户的行为变迁,并进行自动调节。本框架能有效避免用户账号被恶意盗用等现象,对于提高网络安全具有重要意义。

关键词: 网络行为, 行为认证, 身份认证, 访问控制

Abstract:

Towards the problem that the separation between identity authentication and behavior authentication in open network environment, we focus on the rules and characteristics of users’ network behavior. Base on the traditional identity authentication, we put forward the action-based access control model. This paper makes clear the definition of users’ network behavior, take user’s glance time and access path as data source, compared the calculated value gotten from the algorithm with threshold, model it with temporal information and environment information, then realize user’s behavior verification. For new users, we check the behavior with Markov Chains; for existing users, we establish the directed tree of frequent access, using the mean-variance algorithm to detect the behavior. This model can adapt to the changes of user’s behavior automatically. Moreover, this framework can avoid the phenomenon like malicious misappropriate of user accounts, which has significant meanings toward network security.

Key words: network behavior, behavior authentication, identity authentication, access control

中图分类号: