BibliographySchilling, Björn; Koldehofe, Boris; Rothermel, Kurt; Ramachandran, Umakishore: Access Policy Consolidation for Complex Event Processing.
In: IEEE Conference on Networked Systems (NetSys).
University of Stuttgart, Faculty of Computer Science, Electrical Engineering, and Information Technology.
pp. 92-101, english.
IEEE, March 11, 2013.
DOI: 10.1109/NetSys.2013.18.
KeywordsEvent processing; Complex event processing; CEP; Security; Access Control; Bayesian network

In distributed complex event processing, event streams are processed over a chain of subsequent operators. For large-scale applications like a logistic chain these operators may be hosted by different entities and thus are spread over different security domains. Current approaches for complex event processing cannot preserve the privacy of an operator’s incoming event streams. An adversary may infer the original input stream from its legally received event streams.

In this paper we present a fine-grained access management for complex event processing. We show how to enforce privacy of events throughout the chain of dependent operators by specifying appropriate access policies and proposing an algorithm for policy consolidation. Furthermore, we introduce the calculation of obfuscation achieved in a correlation step. This allows us to ignore access requirements once a sufficient obfuscation level has been achieved, the proposed algorithms is capable to reduce the required overhead in the enforcement of access policies. We prove correctness and evaluate the cost in establishing policy consolidation.

