首页> 外文会议>2013 ASE/IEEE International Conference on Social Computing >Access Control Policy Misconfiguration Detection in Online Social Networks
【24h】

Access Control Policy Misconfiguration Detection in Online Social Networks

机译:在线社交网络中的访问控制策略配置错误检测

获取原文
获取原文并翻译 | 示例

摘要

The ability to stay connected with friends online and share information, has accounted for the popularity of online social networking websites. However, the overwhelming task of access control policy management for information shared on these websites has resulted in various mental models of sharing with a false sense of privacy. The misalignment between a user's intended and actual privacy settings causes access control misconfigurations, raising the risk of unintentional privacy leaks. In this paper, we propose a scheme to extract the user's mental model of sharing, enhance this model using information learned from their existing policies, and enable them to compose misconfiguration free policies. We present the possible misconfiguration patterns based on which we scan the Facebook user's access control policies. We implemented a prototype Facebook application of our scheme and conducted a pilot study using Amazon Mechanical Turk. Our preliminary results show that the users' intended policies were significantly different than their actual policies. Our scheme was able to detect the misconfiguration patterns in album policies. However, the reduction in the number of misconfigurations after using our approach was not significant. Participants' perceptions of our proposed policy misconfiguration patterns and the usability of our scheme was positive.
机译:与朋友保持在线联系并共享信息的能力已成为在线社交网站受欢迎的原因。但是,对这些网站上共享的信息进行访问控制策略管理的压倒性任务导致了各种带有虚假隐私感的共享心理模型。用户的预期隐私设置与实际隐私设置之间的不一致会导致访问控制配置错误,从而增加了意外隐私泄漏的风险。在本文中,我们提出了一种方案来提取用户的共享心理模型,使用从他们现有策略中学到的信息来增强此模型,并使他们能够编写无配置错误的策略。我们提供了可能的错误配置模式,基于这些模式我们可以扫描Facebook用户的访问控制策略。我们实施了该计划的Facebook应用程序原型,并使用Amazon Mechanical Turk进行了一项试点研究。我们的初步结果表明,用户的预期策略与他们的实际策略明显不同。我们的方案能够检测专辑策略中的错误配置模式。但是,使用我们的方法后,错误配置的数量减少并不明显。参与者对我们提出的政策配置错误模式和计划可用性的看法是积极的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号