Fuzzy Logic-Based Methodology for Building Access Control Systems Based on Fuzzy Logic is a TELEMETRY publication authored by Vasyl Lytvyn, Anna Bakurova, Oleh Zaritskyi, Anatoliy Gritskevich, Pavlo Hrynchenko, Elina Tereschenko and Dmytro Shyrokorad. The paper was presented at the Modern Data Science Technologies Workshop (MoDaST 2024), held from May 31 to June 1, 2024, in Lviv, Ukraine.
Abstract
The article considers topical issues of analyzing the level of risks of access control systems using the
fuzzy set apparatus. This work aims to improve the efficiency of managing the access control system of
the system components of IoT networks by developing a methodology that combines modern tools and
methods for analyzing data and states of information systems to determine the risk level of the access
control system. In the paper, the information system is considered from the point of view of system
analysis as the interaction of subjects and objects of the system, the relationships between which are
described by access control policies. This paper, for the first time, proposes using object vulnerability
indicators and monitoring anomalies in the system to assess the risk level of the existing access control
system. This approach allows to consider the real state of objects based on the system architecture and
its vulnerability, changes in the system state over time, and to adjust access policies based on the level
of risks assessed using the specified data. The methodology involves the use of modern tools and
software, such as intrusion detection systems (IDS), fuzzy testing, User and Entity Behavior Analytics
(UEBA), User Activity Monitoring (UAM), SBOM, and machine learning approaches. Relevant libraries
and databases: CIS Benchmark, Common Vulnerabilities and Exposures (CVEs), Common Platform
Enumeration (CPE) Dictionary, and Common Vulnerability Scoring System (CVSS) are an integral part
of the methodology, ensuring standardization and integration of the methodology with other
approaches and methods of controlling and monitoring information systems.
Read the full article here.
