Situational Awareness based Risk-Adapatable Access Control in Enterprise Networks
Brian Lee, Roman Vanickis, Franklin Rogelio, Paul Jacob

TL;DR
This paper discusses applying risk-adaptable access control (RAdAC) within zero trust networking (ZTN) for enterprise security, emphasizing dynamic context evaluation and situational awareness integration.
Contribution
It introduces the FURZE framework for fuzzy risk evaluation and explores incorporating enterprise security situational awareness into RAdAC models.
Findings
Development of the FURZE policy management framework
Conceptual integration of SSA into RAdAC for improved security decisions
Application of RAdAC principles to ZTN environments
Abstract
As the computing landscape evolves towards distributed architectures such as Internet of Things (IoT),enterprises are moving away from traditional perimeter based security models toward so called zero trust networking (ZTN) models that treat both the intranet and Internet as equally untrustworthy. Such security models incorporate risk arising from dynamic and situational factors, such as device location and security risk level risk, into the access control decision. Researchers have developed a number of risk models such as RAdAC (Risk Adaptable Access Control) to handle dynamic contexts and these have been applied to medical and other scenarios. In this position paper we describe our ongoing work to apply RAdAC to ZTN. We develop a policy management framework, FURZE, to facilitate fuzzy risk evaluation that also defines how to adapt to dynamically changing contexts. We also consider…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
