首页> 外文会议>IEEE Computer Security Foundations Symposium >Decomposing, Comparing, and Synthesizing Access Control Expressiveness Simulations
【24h】

Decomposing, Comparing, and Synthesizing Access Control Expressiveness Simulations

机译:分解,比较和综合访问控制表达仿真

获取原文

摘要

Access control is fundamental to computer security, and has thus been the subject of extensive formal study. In particular, relative expressiveness analysis techniques have used formal mappings called simulations to explore whether one access control system is capable of emulating another, thereby comparing the expressive power of these systems. Unfortunately, the notions of expressiveness simulation that have been explored vary widely, which makes it difficult to compare results in the literature, and even leads to apparent contradictions between results. Furthermore, some notions of expressiveness simulation make use of non-determinism, and thus cannot be used to define mappings between access control systems that are useful in practical scenarios. In this work, we define the minimum set of properties for an implementable access control simulation, i.e., a deterministic "recipe" for using one system in place of another. We then define a wide range of properties spread across several dimensions that can be enforced on top of this minimum definition. These properties define a taxonomy that can be used to separate and compare existing notions of access control simulation, many of which were previously incomparable. We position existing notions of simulation within our properties lattice by formally proving each simulation's equivalence to a corresponding set of properties. Lastly, we take steps towards bridging the gap between theory and practice by exploring the systems implications of points within our properties lattice. This shows that relative expressive analysis is more than just a theoretical tool, and can also guide the choice of the most suitable access control system for a specific application or scenario.
机译:访问控制是计算机安全的基础,因此已经成为广泛的正式研究的主题。特别是,相对表达能力分析技术已使用称为模拟的形式映射来探索一个访问控制系统是否能够模拟另一个访问控制系统,从而比较这些系统的表达能力。不幸的是,已经探索的表达模拟的概念差异很大,这使得很难比较文献中的结果,甚至导致结果之间明显的矛盾。此外,一些表达性仿真的概念利用了不确定性,因此不能用于定义在实际场景中有用的访问控制系统之间的映射。在这项工作中,我们为可实现的访问控制模拟定义了最小的属性集,即,使用一个系统代替另一个系统的确定性“配方”。然后,我们定义了分布在多个维度上的广泛属性,这些属性可以在此最小定义的基础上强制执行。这些属性定义了一个分类法,可用于分离和比较现有的访问控制模拟概念,其中许多概念以前是无法比拟的。通过将每个模拟的等价形式正式证明为对应的一组属性,我们将现有的模拟概念放置在属性格中。最后,我们通过探索属性格内各点对系统的影响,采取措施弥合理论与实践之间的鸿沟。这表明相对表达分析不仅仅是一种理论工具,而且还可以指导针对特定应用或场景选择最合适的访问控制系统。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号