Font Size: a A A

Research On Key Technologies Of Identification And Access Control For Web Resources

Posted on:2012-01-15Degree:MasterType:Thesis
Country:ChinaCandidate:Y ZhangFull Text:PDF
GTID:2218330371962561Subject:Military communications science
Abstract/Summary:PDF Full Text Request
Along with the development of the Web technology, Web resources sharing becomes more and more frequent. Subsequently Web resources security issues are becoming increasingly prominent. Access control is an important security method that becomes to be one of the key researches in Web security field.Aiming the new requirements of access control model and access control realization technology, this paper studies the access control for Web resources.The main work of this paper is as follows:1. The access control model and realization technology research present situation of Web resource is analyzed deeply. The paper summarizes the advantages and disadvantages of current access control model in Web environment, analyses of the demand of multi-type, multi-grain and transparent access control for Web resources. Puts forward the existing problems of Web resource access control and the solution of this paper.2. An attribute and role based access control model (AR-BAC) which is suitable for Web resources is proposed. The elements, relationship and rules of AR-BAC are formally defined. The security performance, access control grain, and application complexity of the model is analyzed. Analysis implies that the model can satisfy least privilege, separation of duty principles. The AR-BAC can well satisfy the demand of dynamic, flexibility access control for Web resources, lays the theoretical foundation of Web resources access control implementation.3. An access control framework for Web resources (FWRAC) is designed. This paper introduces the components and working process of the FWRAC, and makes deep research on the key technologies. The FWRAC make access control decision based on the theory of the AR-BAC. The FWRAC identify and control the Web resources in the Web data stream by the method of data stream analysis. The FWRAC is coupled loosely with Web application systems, supporting transparent access control for Web resources.4. Research the technology of Web resources identification in Web data stream. According to the demand of Web resources identifitcation for access control and the different characteristics of different grains Web resources. A web page resources identification method based on neural network and a page item resources identification methd based on regular expression description are proposed. The Web resources identification method proposed can make accurate and fast identification for different types of static, dynamic Web resources.5. On the basis of the theory research, An AR-BAC based Web resources permission adjudication module and a data stream analysis based Web resources identification-control module are designed and developed.
Keywords/Search Tags:Web resources, Web resources identification, access control policy, Web resources access control, data stream analysis
PDF Full Text Request
Related items