{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,5,4]],"date-time":"2025-05-04T08:40:09Z","timestamp":1746348009269,"version":"3.40.4"},"reference-count":45,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2014,8,20]],"date-time":"2014-08-20T00:00:00Z","timestamp":1408492800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int. J. Inf. Secur."],"published-print":{"date-parts":[[2015,8]]},"DOI":"10.1007\/s10207-014-0254-9","type":"journal-article","created":{"date-parts":[[2014,8,19]],"date-time":"2014-08-19T19:02:55Z","timestamp":1408474975000},"page":"367-385","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":8,"title":["Integrity-OrBAC: a new model to preserve Critical Infrastructures integrity"],"prefix":"10.1007","volume":"14","author":[{"given":"Abdeljebar","family":"Ameziane El Hassani","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Anas","family":"Abou El Kalam","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Adel","family":"Bouhoula","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ryma","family":"Abassi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Abdellah","family":"Ait Ouahman","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2014,8,20]]},"reference":[{"key":"254_CR1","unstructured":"Public Law 107\u201356-Oct. 26, 2001, Uniting and Srenghtening America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism (USA PATRIOT ACT) ACT of 2001 (2011)"},{"key":"254_CR2","unstructured":"United States Government Accountability Office: critical infrastructure protection\u2014cybersecurity guidance is available, but more can be done to promote its use. Report to congressional requesters, Washington, DC (2011)"},{"key":"254_CR3","doi-asserted-by":"crossref","first-page":"19","DOI":"10.1109\/MSECP.2003.1236231","volume":"1","author":"A Massoud","year":"2003","unstructured":"Massoud, A.: North America\u2019s electricity infrastructure: are we ready for more perfect storms? IEEE Secur. Priv. 1, 19\u201325 (2003)","journal-title":"IEEE Secur. Priv."},{"key":"254_CR4","unstructured":"Moteff, J., Parfomak, P.: CRS report for congress\u2014critical infrastructure and key assets: definition and identification (2004)"},{"key":"254_CR5","unstructured":"ISO\/IEC 15408\u2014Common criteria for information technology security evaluation\u2014Part 1: introduction and general model, Version 3.1, Revision 4 (2012)"},{"key":"254_CR6","unstructured":"Agence Nationale de la S\u00e9curit\u00e9 des Syst\u00e8mes d\u2019Information (ANSSI): EBIOS\u2014expression des besoins et identification des objectifs de S\u00e9curit\u00e9. http:\/\/www.ssi.gouv.fr\/fr\/guides-et-bonnes-pratiques\/outils-methodologiques\/ebios-2010-expression-des-besoins-et-identification-des-objectifs-de-securite.html . Accessed 25 Feb 2014"},{"key":"254_CR7","unstructured":"MEHARI, Club de la S\u00e9curit\u00e9 de l\u2019Information Fran\u00e7ais (CLUSIF). http:\/\/www.clusif.asso.fr\/fr\/production\/mehari\/ . Accessed 25 Aug 2013"},{"key":"254_CR8","unstructured":"International Standard ISO\/IEC 27005:2008, Information technology\u2014security techniques\u2014information security risk management (2008)"},{"key":"254_CR9","unstructured":"Lampson, B.: Protection. In: $$5^{th}$$ 5 th Princeton symposium on information sciences and systems, pp. 437\u2013443 (1971)"},{"key":"254_CR10","doi-asserted-by":"crossref","unstructured":"Bell, D., LaPadula, L.: Secure computer systems: unified exposition and multics interpretation. Technical Report ESD-TR-75-306, MTR-2997, MITRE, Bedford, MA, USA (1975)","DOI":"10.21236\/ADA023588"},{"key":"254_CR11","unstructured":"Biba, K.: Integrity considerations for secure computer systems. Technical Report ESD-TR-76-372, ESD\/AFSC, Hanscom AFB, Bedford, MA, USA (1977)"},{"issue":"3","key":"254_CR12","doi-asserted-by":"crossref","first-page":"224","DOI":"10.1145\/501978.501980","volume":"4","author":"DF Ferraiolo","year":"2001","unstructured":"Ferraiolo, D.F., Sandhu, R., Gavrila, S., Kuhn, D.R., Chandramouli, R.: Proposed NIST Standard for Role-Based Access Control. ACM Trans. Inf. Syst. Secur. 4(3), 224\u2013274 (2001)","journal-title":"ACM Trans. Inf. Syst. Secur."},{"key":"254_CR13","doi-asserted-by":"crossref","unstructured":"Thomas, R.K.: TMAC: a primitive for Applying RBAC in collaborative environment. In: $$2^{nd}$$ 2 nd ACM workshop on RBAC, pp. 13\u201319 (1997)","DOI":"10.1145\/266741.266748"},{"key":"254_CR14","doi-asserted-by":"crossref","unstructured":"Thomas, R.K., Sandhu, R.: Task-based authorization controls (TBAC): a family of models for active and enterprise-oriented authorization management. In: $$11^{th}$$ 11 th IFIP working conference on database security, Lake Tahoe, California (1997)","DOI":"10.1007\/978-0-387-35285-5_10"},{"key":"254_CR15","doi-asserted-by":"crossref","unstructured":"Fink, T., Koch, M., Oancea, C.: Specification and enforcement of access control in heterogeneous distributed applications. In: Proceedings of the international conference on web services, pp. 88\u2013100 (2003)","DOI":"10.1007\/978-3-540-39872-1_8"},{"key":"254_CR16","doi-asserted-by":"crossref","unstructured":"Sandhu, R., Park, J.: Usage control: a vision for next generation access control. MMM-ACNS, pp. 17\u201331 (2003)","DOI":"10.1007\/978-3-540-45215-7_2"},{"key":"254_CR17","doi-asserted-by":"crossref","unstructured":"Benferhat, S., El Baida, R., Cuppens, F.: A stratification-based approach for handling conflicts in access control. In: $$8^{th}$$ 8 th ACM symposium on access control models and technologies (SACMAT\u201903), pp. 189\u2013195 (2003)","DOI":"10.1145\/775412.775437"},{"key":"254_CR18","unstructured":"Abou El Kalam, A., El Baida, R., Balbiani, P., Benferhat, S., Cuppens, F., Deswarte, Y., Mi\u00e8ge, A., Saurel, C., Trouessin, G.: Organization based access control. In: $$4^{th}$$ 4 th international workshop on policies for distributed systems and networks (POLICY 2003), pp. 120\u2013131 (2003)"},{"key":"254_CR19","unstructured":"Krause, M., Tipton, H.F.: Handbook of information security management. Auerbach Publications\/CRC Press LLC, Boca Raton, FL, USA (1998)"},{"key":"254_CR20","doi-asserted-by":"crossref","unstructured":"Goguen, J.A., Meseguer, J.: Security policies and security models. In: IEEE symposium on security and privacy, pp. 11\u201320 (1982)","DOI":"10.1109\/SP.1982.10014"},{"key":"254_CR21","doi-asserted-by":"crossref","unstructured":"Clark, D., Wilson, D.: A comparison of commercial and military computer security policies. In: IEEE symposium on security and privacy, pp. 184\u2013194 (1987)","DOI":"10.1109\/SP.1987.10001"},{"key":"254_CR22","doi-asserted-by":"crossref","unstructured":"Brewer, D.F.C., Nash, M.J.: The Chinese wall security policy. In: IEEE symposium on security and privacy, pp. 206\u2013214 (1988)","DOI":"10.1109\/SECPRI.1989.36295"},{"key":"254_CR23","doi-asserted-by":"crossref","unstructured":"Totel, E., Blanquart, J.P., Deswarte, Y., Powell, D.: Supporting multiple levels of criticality. In: $$28^{th}$$ 28 th IEEE fault tolerant computing symposium, pp. 70\u201379 (1998)","DOI":"10.1109\/FTCS.1998.689456"},{"key":"254_CR24","doi-asserted-by":"crossref","unstructured":"Ameziane El Hassani, A., Abou El Kalam, A., Ait Ouahman, A.: Integrity-organization based access control for critical infrastructure systems. In: $$6^{th}$$ 6 th Annual IFIP working group 11.10 international conference on critical infrastructure protection, Washington, DC, IFIP AICT 390, pp. 31\u201342 (2012)","DOI":"10.1007\/978-3-642-35764-0_3"},{"key":"254_CR25","doi-asserted-by":"crossref","unstructured":"Abou El Kalam A.A., Ameziane El Hassani, A., Ait Ouahman, A.: Integrity-OrBAC: an OrBAC enhancement that takes into account integrity. In: $$8^{th}$$ 8 th international conference on intelligent systems: theories and applications, Rabat, Morocco (2013)","DOI":"10.1109\/SITA.2013.6560820"},{"issue":"4","key":"254_CR26","doi-asserted-by":"crossref","first-page":"154","DOI":"10.1016\/j.ijcip.2009.08.005","volume":"2","author":"A Abou El Kalam","year":"2009","unstructured":"Abou El Kalam, A., Deswarte, Y., Baina, A., Kaaniche, M.: PolyOrBAC: a security framework for critical infrastructures. Int. J. Crit. Infrastruct. Prot. 2(4), 154\u2013169 (2009)","journal-title":"Int. J. Crit. Infrastruct. Prot."},{"key":"254_CR27","doi-asserted-by":"crossref","first-page":"44","DOI":"10.1109\/MSP.2008.158","volume":"6","author":"A Neves Bessani","year":"2008","unstructured":"Neves Bessani, A., Sousa, P., Correia, M., Verissimo, P.: The CRUTIAL way of critical infrastructure protection. IEEE Secur. Priv. 6, 44\u201351 (2008)","journal-title":"IEEE Secur. Priv."},{"key":"254_CR28","unstructured":"Dunn, M., Mauer, V.: International CIIP handbook: vol. Analyzing issues, challenges, and prospects. Center for Security Studies, ETH Zurich, II (2006)"},{"key":"254_CR29","unstructured":"Deswarte, Y., M\u00e9, L.: S\u00e9curit\u00e9 des r\u00e9seaux et syst\u00e8mes r\u00e9partis. Hermes Science Publications (2003)"},{"key":"254_CR30","doi-asserted-by":"crossref","unstructured":"Amoroso, E., Merritt, M.: Composing system integrity using I\/O automata. In: $$10^{th}$$ 10 th annual computer security applications conference, pp. 34\u201343 (1994)","DOI":"10.1109\/CSAC.1994.367321"},{"key":"254_CR31","doi-asserted-by":"crossref","unstructured":"Saltzer, J.H., Schroeder, M.D.: The protection of information in computer systems. Proc. IEEE 63(9), 1278\u20131308 (1975)","DOI":"10.1109\/PROC.1975.9939"},{"key":"254_CR32","volume-title":"Computer security : art and science","author":"M Bishop","year":"2003","unstructured":"Bishop, M.: Computer security : art and science. Addison-Wesley, Boston, MA (2003)"},{"key":"254_CR33","unstructured":"Cuppens, F., Mi\u00e8ge, A.: Modeling contexts in the Or-BAC model. In: $$19^{th}$$ 19 th annual computer security applications conference, Las Vegas, (2003)"},{"key":"254_CR34","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1016\/j.entcs.2007.01.064","volume":"186","author":"F Cuppens","year":"2007","unstructured":"Cuppens, F., CuppensBoulahia, N., Ghorbel, M.B.: High level conflict management strategies in advanced access control models. Electron. Notes Theor. Comput. Sci. 186, 3\u201326 (2007)","journal-title":"Electron. Notes Theor. Comput. Sci."},{"key":"254_CR35","unstructured":"Cuppens, F., CuppensBoulahia, N., Mi\u00e8ge, A.: Inheritance hierarchies in the OrBAC model and application in a network environment. In: $$2^{nd}$$ 2 nd foundations of computer security workshop (FCS\u201904), Turku, Finland (2004)"},{"key":"254_CR36","doi-asserted-by":"crossref","unstructured":"Cuppens, F., Mi\u00e8ge, A.: Administration model for OrBAC. In: Workshops of OTM 2003, on the move to meaningful internet systems, lecture notes in computer science, Springer, Vol. 2889, pp. 754\u2013768, Italy (2003)","DOI":"10.1007\/978-3-540-39962-9_76"},{"key":"254_CR37","unstructured":"Abou El Kalam, A., Deswarte, Y.: MultiOrBAC: a new access control model for distributed, heterogeneous and collaborative systems. In: IEEE symposium on systems and information security, Sao Paulo, Brazil (2006)"},{"key":"254_CR38","doi-asserted-by":"crossref","unstructured":"Baina, A., Abou El Kalam, A., Deswarte, Y., Kaaniche, M.: A collaborative access control framework for critical infrastructures. In: $$2^{nd}$$ 2 nd annual IFIP working group 11.10 international conference on critical infrastructure protection, Arlington, VA, USA (2008)","DOI":"10.1016\/j.ijcip.2009.08.005"},{"key":"254_CR39","doi-asserted-by":"crossref","unstructured":"Cuppens, F., CuppensBoulahia, N., Coma, C.: O2O: virtual private organizations to manage security policy interoperability. In: $$2^{nd}$$ 2 nd international conference on information systems security, ICISS 2006, India (2006)","DOI":"10.1007\/11961635_7"},{"issue":"5","key":"254_CR40","first-page":"2452","volume":"2","author":"N Essaouini","year":"2011","unstructured":"Essaouini, N., Abou El Kalam, A., Ait Ouahman, A.: Access control policy: a framework to enforce recommendations. Int. J. Comput. Sci. Inf. Technol. 2(5), 2452\u20132463 (2011)","journal-title":"Int. J. Comput. Sci. Inf. Technol."},{"key":"254_CR41","unstructured":"eXtensible Access Control Markup Language (XACML) Version 3.0, OASIS standard (2013). http:\/\/docs.oasis-open.org\/xacml\/3.0\/xacml-3.0-core-spec-os-en.html . Accessed 1 Sept 2013"},{"key":"254_CR42","unstructured":"Core and hierarchical role based access control (RBAC) profile of XACML v2.0, OASIS standard (2005). http:\/\/docs.oasis-open.org\/xacml\/2.0\/access_control-xacml-2.0-rbac-profile1-spec-os . Accessed 5 Sept 2013"},{"key":"254_CR43","doi-asserted-by":"crossref","unstructured":"Verissimo, P., Neves, N.F., Correia, M., Deswarte, Y., Abou El Kalam, A., Bondavalli, A., Daidone, A.: The CRUTIAL architecture for critical information infrastructures. Architecting dependable systems V, LNCS, Vol. 5135, Springer, pp. 1\u201327 (2008)","DOI":"10.1007\/978-3-540-85571-2_1"},{"key":"254_CR44","doi-asserted-by":"crossref","unstructured":"Anderson, M., Montague, P., Long, B.: A context-based integrity framework. In: $$19^{th}$$ 19 th Asia-Pacific software engineering conference, pp. 1\u20139 (2012)","DOI":"10.1109\/APSEC.2012.90"},{"key":"254_CR45","doi-asserted-by":"crossref","unstructured":"Xu, Q., Liu, G.: Configuring Clark-Wilson integrity model to enforce flexible protection. In: International conference on computational intelligence and security, pp. 15\u201320 (2009)","DOI":"10.1109\/CIS.2009.249"}],"container-title":["International Journal of Information Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-014-0254-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s10207-014-0254-9\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-014-0254-9","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,5,4]],"date-time":"2025-05-04T08:19:50Z","timestamp":1746346790000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s10207-014-0254-9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014,8,20]]},"references-count":45,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2015,8]]}},"alternative-id":["254"],"URL":"https:\/\/doi.org\/10.1007\/s10207-014-0254-9","relation":{},"ISSN":["1615-5262","1615-5270"],"issn-type":[{"type":"print","value":"1615-5262"},{"type":"electronic","value":"1615-5270"}],"subject":[],"published":{"date-parts":[[2014,8,20]]}}}