首页> 外文会议>International conference on intelligent software methodologies, tools, and techniques >AVTAC : A Framework for Automatic Auditing of Access Control in Windows and Linux Systems
【24h】

AVTAC : A Framework for Automatic Auditing of Access Control in Windows and Linux Systems

机译:AVTAC:Windows和Linux系统中自动审计访问控制的框架

获取原文

摘要

Access control validation (also called conformity or compliance) consists in verifying at a regular basis whether the implemented access control rules are consistent and complete with respect to a given security policy or not. The compliance of some critical accesses needs to be monthly confirmed while other less critical assesses might me yearly analyzed. The result of the analysis is a detailed report that could be shown to an inspector. All important security referentials such as ISO 27001, COBIT, NIST 800-53 and HIPA recommend that conformity analysis should be done at regular intervals. For a small company, it would be possible to manually validate the access control policy. However for companies with thousands of employees, we need the help of automatic tools to accomplish this task. This paper introduces AVTAR (Automatic Validation Tool of Access Control) which is a framework that can automatically extract access control policies in Windows and Linux operating systems in order to analyze them.
机译:访问控制验证(也称为一致性或遵从性)在于,定期验证所实施的访问控制规则相对于给定的安全策略是否一致且完整。一些关键访问的合规性需要每月进行确认,而其他不太关键的评估则可能需要我每年进行分析。分析的结果是一份详细的报告,可以显示给检查员。所有重要的安全参考标准,例如ISO 27001,COBIT,NIST 800-53和HIPA,都建议定期进行符合性分析。对于小型公司,可以手动验证访问控制策略。但是,对于拥有数千名员工的公司,我们需要自动工具的帮助才能完成此任务。本文介绍了AVTAR(访问控制的自动验证工具),该框架可以自动提取Windows和Linux操作系统中的访问控制策略,以便对其进行分析。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号