User behaviour-based access control for social media with qualitative research and Bayesian modelling

  • Sara McCloskey
  • , John Herbert

Research output: Chapter in Book/Report/Conference proceedingsChapterpeer-review

Abstract

Access control systems protect against unauthorised access to resources, where security policies define what is allowed, and what is not. Traditional models focus on protecting access to files, directories, and processes; however, the rise of social media has brought about a need for a new type of model – one focused on sharing rather than protecting, and based on user behaviour rather than a technical specification. A methodology is proposed to perform what we call user behaviour-based access control, building access control policies through analysis of user behaviour. The process involves a combination of qualitative research practices and probabilistic reasoning to address the problems of uncertainty and diversity associated with the study of human behaviour. Data collection and analysis is achieved through semi-structured interviewing and grounded theory techniques. The results of the analysis are used to build a probabilistic model, in the form of a Bayesian network, which implements access control. Requests containing observations of the attribute values are pushed through the network to produce a probabilistic access control decision. The method has been evaluated on real social media users, and has been shown to be effective in capturing and mechanising user sharing preferences.

Original languageEnglish
Title of host publicationProceedings - 2019 IEEE 43rd Annual Computer Software and Applications Conference, COMPSAC 2019
EditorsVladimir Getov, Jean-Luc Gaudiot, Nariyoshi Yamai, Stelvio Cimato, Morris Chang, Yuuichi Teranishi, Ji-Jiang Yang, Hong Va Leong, Hossian Shahriar, Michiharu Takemoto, Dave Towey, Hiroki Takakura, Atilla Elci, Susumu Takeuchi, Satish Puri
PublisherIEEE Computer Society
Pages575-579
Number of pages5
ISBN (Electronic)9781728126074
DOIs
Publication statusPublished - Jul 2019
Event43rd IEEE Annual Computer Software and Applications Conference, COMPSAC 2019 - Milwaukee, United States
Duration: 15 Jul 201919 Jul 2019

Publication series

NameProceedings - International Computer Software and Applications Conference
Volume2
ISSN (Print)0730-3157

Conference

Conference43rd IEEE Annual Computer Software and Applications Conference, COMPSAC 2019
Country/TerritoryUnited States
CityMilwaukee
Period15/07/1919/07/19

Keywords

  • Access control
  • Bayesian network
  • Qualitative research
  • Social media
  • User behaviour

Fingerprint

Dive into the research topics of 'User behaviour-based access control for social media with qualitative research and Bayesian modelling'. Together they form a unique fingerprint.

Cite this