{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,18]],"date-time":"2026-03-18T01:21:51Z","timestamp":1773796911440,"version":"3.50.1"},"publisher-location":"Berlin, Heidelberg","reference-count":30,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783642288784","type":"print"},{"value":"9783642288791","type":"electronic"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2012]]},"DOI":"10.1007\/978-3-642-28879-1_14","type":"book-chapter","created":{"date-parts":[[2012,3,12]],"date-time":"2012-03-12T10:00:09Z","timestamp":1331546409000},"page":"206-220","source":"Crossref","is-referenced-by-count":6,"title":["Risk-Based Auto-delegation for Probabilistic Availability"],"prefix":"10.1007","author":[{"given":"Leanid","family":"Krautsevich","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fabio","family":"Martinelli","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Charles","family":"Morisset","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Artsiom","family":"Yautsiukhin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"14_CR1","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"254","DOI":"10.1007\/978-3-540-70567-3_20","volume-title":"Data and Applications Security XXII","author":"C.A. Ardagna","year":"2008","unstructured":"Ardagna, C.A., De Capitani di Vimercati, S., Grandison, T., Jajodia, S., Samarati, P.: Regulating Exceptions in Healthcare Using Policy Spaces. In: Atluri, V. (ed.) DAS 2008. LNCS, vol.\u00a05094, pp. 254\u2013267. Springer, Heidelberg (2008)"},{"key":"14_CR2","doi-asserted-by":"crossref","unstructured":"Brewer, D.F.C., Nash, M.J.: The Chinese Wall Security Policy. In: Proceedings of the IEEE Symposium on Security and Privacy, pp. 329\u2013339 (May 1989)","DOI":"10.1109\/SECPRI.1989.36295"},{"key":"14_CR3","doi-asserted-by":"crossref","unstructured":"Brucker, A.D., Petritsch, H., Schaad, A.: Delegation assistance. In: IEEE International Workshop on Policies for Distributed Systems and Networks, pp. 84\u201391 (2009)","DOI":"10.1109\/POLICY.2009.35"},{"key":"14_CR4","doi-asserted-by":"crossref","unstructured":"Chander, A., Mitchell, J.C., Dean, D.: A state-transition model of trust management and access control. In: Proceedings of the 14th IEEE Computer Security Foundations Workshop, pp. 27\u201343. IEEE Computer Society Press (2001)","DOI":"10.1109\/CSFW.2001.930134"},{"key":"14_CR5","unstructured":"Chen, L., Crampton, J.: Risk-aware role-based access control. In: Proceedings of 7th International Workshop on Security and Trust Management (to appear, 2011)"},{"key":"14_CR6","unstructured":"Cheng, P.-C., Karger, P.A.: Risk modulating factors in risk-based access control for information in a manet. Technical Report RC24494, IBM T.J. Watson (2008)"},{"key":"14_CR7","unstructured":"Cheng, P.-C., Rohatgi, P.: IT security as risk management: A research perspective. Technical Report RC24529, IBM T.J. Watson (April 2008)"},{"key":"14_CR8","doi-asserted-by":"crossref","unstructured":"Cheng, P.-C., Rohatgi, P., Keser, C., Karger, P.A., Wagner, G.M., Reninger, A.S.: Fuzzy multi-level security: An experiment on quantified risk-adaptive access control. In: Proceedings of the IEEE Symposium on Security and Privacy, pp. 222\u2013230 (2007)","DOI":"10.1109\/SP.2007.21"},{"key":"14_CR9","unstructured":"Computing\u00a0Research Association. Four grand challenges in trustworthy computing (November 2003)"},{"key":"14_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-642-22444-7_1","volume-title":"Security and Trust Management","author":"J. Crampton","year":"2011","unstructured":"Crampton, J., Morisset, C.: An Auto-delegation Mechanism for Access Control Systems. In: Cuellar, J., Lopez, J., Barthe, G., Pretschner, A. (eds.) STM 2010. LNCS, vol.\u00a06710, pp. 1\u201316. Springer, Heidelberg (2011)"},{"key":"14_CR11","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1109\/MSP.2006.170","volume":"4","author":"G. Cybenko","year":"2006","unstructured":"Cybenko, G.: Why johnny can\u2019t evaluate security risk. IEEE Security and Privacy\u00a04, 5 (2006)","journal-title":"IEEE Security and Privacy"},{"key":"14_CR12","doi-asserted-by":"crossref","unstructured":"Diep, N.N., Hung, L.X., Zhung, Y., Lee, S., Lee, Y.-K., Lee, H.: Enforcing access control using risk assessment. In: Proceedings of the Fourth European Conference on Universal Multiservice Networks, Washington, DC, USA, pp. 419\u2013424 (2007)","DOI":"10.1109\/ECUMN.2007.19"},{"key":"14_CR13","unstructured":"Ferraiolo, D.F., Kuhn, D.R.: Role-based access control. In: Proceedings of the 15th National Computer Security Conference, pp. 554\u2013563 (1992)"},{"key":"14_CR14","doi-asserted-by":"publisher","first-page":"415","DOI":"10.1109\/ISA.2008.114","volume-title":"Proceedings of the 2008 International Conference on Information Security and Assurance","author":"Y. Han","year":"2008","unstructured":"Han, Y., Hori, Y., Sakurai, K.: Security policy pre-evaluation towards risk analysis. In: Proceedings of the 2008 International Conference on Information Security and Assurance, pp. 415\u2013420. IEEE, Washington, DC (2008)"},{"key":"14_CR15","doi-asserted-by":"crossref","unstructured":"Hanson, S.O.: Decision theory: A brief introduction (August 1994)","DOI":"10.1007\/978-1-349-23381-6_1"},{"issue":"8","key":"14_CR16","doi-asserted-by":"publisher","first-page":"461","DOI":"10.1145\/360303.360333","volume":"19","author":"M.A. Harrison","year":"1976","unstructured":"Harrison, M.A., Ruzzo, W.L., Ullman, J.D.: Protection in operating systems. Communications of the ACM\u00a019(8), 461\u2013471 (1976)","journal-title":"Communications of the ACM"},{"key":"14_CR17","unstructured":"Kephart, J.: The utility of utility: Policies for self-managing systems. In: Proceedings of Policies for Distributed Systems and Networks (to appear, 2011)"},{"key":"14_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"35","DOI":"10.1007\/978-3-642-22444-7_3","volume-title":"Security and Trust Management","author":"L. Krautsevich","year":"2011","unstructured":"Krautsevich, L., Lazouski, A., Martinelli, F., Yautsiukhin, A.: Influence of Attribute Freshness on Decision Making in Usage Control. In: Cuellar, J., Lopez, J., Barthe, G., Pretschner, A. (eds.) STM 2010. LNCS, vol.\u00a06710, pp. 35\u201350. Springer, Heidelberg (2011)"},{"key":"14_CR19","doi-asserted-by":"crossref","unstructured":"Krautsevich, L., Lazouski, A., Martinelli, F., Yautsiukhin, A.: Risk-aware usage decision making in highly dynamic systems. In: Proceedings of the Fifth International Conference on Internet Monitoring and Protection. IEEE (2010)","DOI":"10.1109\/ICIMP.2010.13"},{"key":"14_CR20","doi-asserted-by":"crossref","unstructured":"Krautsevich, L., Lazouski, A., Martinelli, F., Yautsiukhin, A.: Risk-based usage control for service oriented architecture. In: Proceedings of the 18th Euromicro International Conference on Parallel, Distributed and Network-Based Computing. IEEE (2010)","DOI":"10.1109\/PDP.2010.46"},{"key":"14_CR21","unstructured":"Lampson, B.: Protection. In: Proceedings of the 5th Annual Princeton Conference on Information Sciences and Systems, pp. 437\u2013443. Princeton University (1971)"},{"key":"14_CR22","doi-asserted-by":"crossref","first-page":"239","DOI":"10.3233\/JCS-1996-42-308","volume":"4","author":"L.J. LaPadula","year":"1996","unstructured":"LaPadula, L.J., Bell, D.E.: Secure Computer Systems: A Mathematical Model. Journal of Computer Security\u00a04, 239\u2013263 (1996)","journal-title":"Journal of Computer Security"},{"key":"14_CR23","doi-asserted-by":"publisher","first-page":"13","DOI":"10.1109\/SecTech.2008.50","volume-title":"Proceedings of the 2008 International Conference on Security Technology","author":"Y. Li","year":"2008","unstructured":"Li, Y., Sun, H., Chen, Z., Ren, J., Luo, H.: Using trust and risk in access control for grid environment. In: Proceedings of the 2008 International Conference on Security Technology, pp. 13\u201316. IEEE, Washington, DC (2008)"},{"key":"14_CR24","unstructured":"McGraw, R.W.: Risk-adaptable access control, RAdAC (2007), http:\/\/csrc.nist.gov\/news_events\/privilege-management-workshop\/radac-Paper0001.pdf (August 16, 2009)"},{"key":"14_CR25","volume-title":"Proceedings of the 15th ACM New Security Paradigms Workshop","author":"I. Molloy","year":"2008","unstructured":"Molloy, I., Cheng, P.-C., Rohatgi, P.: Trading in risk: Using markets to improve access control. In: Proceedings of the 15th ACM New Security Paradigms Workshop, Lake TAhoe, CA, USA. ACM, New York (2008)"},{"key":"14_CR26","doi-asserted-by":"crossref","unstructured":"Molloy, I., Dickens, L., Morisset, C., Cheng, P.-C., Lobo, J., Russo, A.: Risk-based access control decisions under uncertainty. Technical Report RC25121, IBM T.J. Watson (September 2011)","DOI":"10.1145\/2133601.2133622"},{"key":"14_CR27","doi-asserted-by":"crossref","first-page":"250","DOI":"10.1145\/1755688.1755719","volume-title":"Proceedings of the 5th ACM Symposium on Information, Computer and Communications Security","author":"Q. Ni","year":"2010","unstructured":"Ni, Q., Bertino, E., Lobo, J.: Risk-based access control systems built on fuzzy inferences. In: Proceedings of the 5th ACM Symposium on Information, Computer and Communications Security, pp. 250\u2013260. ACM, New York (2010)"},{"issue":"4","key":"14_CR28","doi-asserted-by":"crossref","first-page":"447","DOI":"10.3233\/JCS-2007-15402","volume":"15","author":"C. Skalka","year":"2007","unstructured":"Skalka, C., Wang, X.S., Chapin, P.: Risk management for distributed authorization. J. Comput. Secur.\u00a015(4), 447\u2013489 (2007)","journal-title":"J. Comput. Secur."},{"key":"14_CR29","doi-asserted-by":"publisher","first-page":"455","DOI":"10.1142\/S0218843003000814","volume":"12","author":"J. Wainer","year":"2003","unstructured":"Wainer, J., Barthelmess, P., Kumar, A.: W-RBAC - a workflow security model incorporating controlled overriding of constraints. International Journal of Cooperative Information Systems\u00a012, 455\u2013485 (2003)","journal-title":"International Journal of Cooperative Information Systems"},{"key":"14_CR30","doi-asserted-by":"crossref","unstructured":"Zhang, L., Brodsky, A., Jajodia, S.: Toward information sharing: Benefit and risk access control (BARAC). In: Proceedings of the 7th IEEE International Workshop on Policies for Distributed Systems and Networks, Washington, DC, USA, pp. 45\u201353 (2006)","DOI":"10.1109\/POLICY.2006.36"}],"container-title":["Lecture Notes in Computer Science","Data Privacy Management and Autonomous Spontaneus Security"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-28879-1_14","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,3,22]],"date-time":"2025-03-22T23:51:41Z","timestamp":1742687501000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-28879-1_14"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012]]},"ISBN":["9783642288784","9783642288791"],"references-count":30,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-28879-1_14","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2012]]}}}