Privacy-enhancing Access Control Mechanism in Distributed Online Social Network
نویسنده
چکیده
Dramatic growth in the number of subscribers in Online Social Networks (OSNs), such as Facebook, MySpace, Orkut, etc. shows their increasing popularity among people from different ages and sectors. However, currently, the users need to put complete trust on OSN service providers, to protect their sensitive information because of centralized access control at the providers. Taking advantage of this infrastructure, OSN service providers can expose their subscribers’ personal information for targeted advertisements, or anything that is mentioned in the terms of the privacy agreement, including to change the terms. To give complete access control to the users over their data, there must be an alternative infrastructure, which removes dependence on OSN service providers. In order to address this privacy issue, Sonja Buchegger and Anwitaman Datta proposed 2-tier peer-to-peer architecture for social networks, called PeerSoN. The goal of this master’s thesis is to evaluate the suitability of eXtensible Access Control Markup Language (XACML) for Distributed Online Social Network (DOSN) access control and privacy preservation. To do that, firstly, we determine the requirements for access control in DOSN, and present a structure for users’ profiles. Due to the wide ranges of requirements, we propose to use rule-based access control for the users in OSN, where the rules are based on both static and dynamic constraints. Secondly, in order to investigate whether these policies can be expressed in XACML or not, we implement some common authorization policies using SunXACML, an open source implementation of standard XACML version 2.0. Thirdly, to enhance privacy regarding authentication and enforcement, we offer to use secret key based authentication of SAML, and one of the XACML supported web or application servers, such as JBoss Application server, Fedora server, in conjunction with XACML. Finally, we evaluate our architecture against three types of attackers; namely, users from social links, users form outside of social links, and random persons, and claim that our mechanism is well protected against different threats, such as unauthorized access, impersonation attacks, identity theft, information leakage via friendship links, etc., specifically, when each user’s profile is stored on his
منابع مشابه
A centralized privacy-preserving framework for online social networks
There are some critical privacy concerns in the current online social networks (OSNs). Users' information is disclosed to different entities that they were not supposed to access. Furthermore, the notion of friendship is inadequate in OSNs since the degree of social relationships between users dynamically changes over the time. Additionally, users may define similar privacy settings for their f...
متن کاملEnhancing Security and Privacy in Online Social Networks
Online Social Networks (OSNs) have become ubiquitous and changed the way that users interact online. There has been an enormous growth in the usage of OSNs in the past few years as users utilize OSNs to share a variety of information. This vast amount of information is valuable, and therefore introduces several privacy risks and challenges. In this research proposal we analyze the security and ...
متن کاملOnline Social Networks for a Multiparty Access Control Model and Mechanisms
Online Social Networks (OSNs) are essentially designed to facilitate people to share personal and public information and make social connections with others. These OSNs propose goodlooking means for digital social communications and information distribution, but also raise a number of security and privacy issues. Whereas OSNs allow users to control access to shared data, at the moment they do n...
متن کاملSocial Networking : Security , Privacy , and Applications By
Online social networks have become ubiquitous and changed the way that users interact online. There has been an enormous growth in the usage of online social networking in the past few years as users share a variety of information including personal profiles, pictures, and messages to socialize with their friends in the Internet. Besides, several special purpose social networks have emerged to ...
متن کاملLotusNet: Tunable privacy for distributed online social network services
The evolution of the role of online social networks in the Web has led to a collision between private, public and commercial spheres that have been inevitably connected together in social networking services since their beginning. The growing awareness on the opaque data management operated by many providers reveals that a privacy-aware service that protects user information from privacy leaks ...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2011