【24h】

When Role Models Have Flaws

机译:当榜样有缺陷时

获取原文

摘要

Modern multiuser software systems have adopted Role- Based Access Control (RBAC) for authorization management. This paper presents a formal model for RBAC policy validation and a static-analysis model for RBAC systems that can be used to (i) identify the roles required by users to execute an enterprise application, (ii) detect potential inconsistencies caused by principal-delegation policies, which are used to override a user's role assignment, (iii) report if the roles assigned to a user by a given policy are redundant or insufficient, and (iv) report vulnerabilities that can result from unchecked intra-component accesses. The algorithms described in this paper have been implemented as part of IBM's Enterprise Security Policy Evaluator (ESPE) tool. Experimental results show that the tool found numerous policy flaws, including ten previously unknown flaws from two production-level applications, with no false-positive reports.
机译:现代多用户软件系统已采用基于角色的访问控制(RBAC)进行授权管理。本文介绍了用于RBAC策略验证的正式模型和用于RBAC系统的静态分析模型,这些模型可用于(i)识别用户执行企业应用程序所需的角色,(ii)检测由委托委派引起的潜在不一致用于覆盖用户角色分配的策略;(iii)报告给定策略分配给用户的角色是否多余或不足;以及(iv)报告由未经检查的组件内访问导致的漏洞。本文中描述的算法已作为IBM企业安全策略评估器(ESPE)工具的一部分实现。实验结果表明,该工具发现了许多策略缺陷,其中包括来自两个生产级应用程序的十个以前未知的缺陷,并且没有错误肯定的报告。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号