首页> 外文会议>ACM symposium on access control models and technologies >A Framework for Verification and Optimal Reconfiguration of Event-driven Role Based Access Control Policies
【24h】

A Framework for Verification and Optimal Reconfiguration of Event-driven Role Based Access Control Policies

机译:基于事件驱动的角色访问控制策略的验证和最佳重新配置的框架

获取原文

摘要

Role based access control (RBAC) is the de facto model used for advanced access control due to its inherent richness and flexibility. Despite its great success at modeling a variety of organizational nereis, maintaining large complex policies is a challenging problem. Conflicts within policies can expose, the underlying system to numerous vulnerabilities and security risks. Therefore, more comprehensive verification tools for RBAC need to be developed to enable effective access control. In this paper, we propose a verification framework for detection and resolution of inconsistencies and conflicts in policies modeled through event-driven RBAC. an important subset of generalized temporal RBAC applicable to many domains, such as SCADA systems. We define the conflict, resolution problem and propose an integer programming based heuristic. The proposed approach is generic and can be tuned to a variety of opt irnality measures.
机译:基于角色的访问控制(RBAC)是由于其固有的丰富性和灵活性而用于高级访问控制的DE Facto模型。尽管在建模各种组织的小河方面取得了巨大成功,但维持大量复杂的政策是一个具有挑战性的问题。政策中的冲突可能会使潜在的系统曝光,以众多漏洞和安全风险。因此,需要开发RBAC的更全面的验证工具以实现有效的访问控制。在本文中,我们提出了一种验证框架,用于检测和解决通过事件驱动的RBAC建模的政策中的不一致性和冲突。适用于许多域的广义时间RBAC的一个重要子集,例如SCADA系统。我们定义了冲突,解决问题,并提出了基于整数的基于程序的启发式。所提出的方法是通用的,可以调整到各种OPT IRNALY措施。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号