首页> 外文会议>International conference on future data and security engineering >Adventures in the Analysis of Access Control Policies
【24h】

Adventures in the Analysis of Access Control Policies

机译:访问控制策略分析中的历险记

获取原文

摘要

Access Control is becoming increasingly important for today's ubiquitous systems which provide mechanism to prevent sensitive resources against unauthorized users. In access control models, the administration of access control policies is an important task that raises a crucial analysis problem: if a set of administrators can give a user an unauthorized access permission. In this paper, we consider the analysis problem in the context of the Administrative Role-Based Access Control (ARBAC), one of the most widespread administrative models. We describe how we design heuristics to enable an analysis tool, called asaspXL, to scale up to handle large and complex ARBAC policies and a sequence of analysis problems. An extensive experimentation shows that the proposed heuristics play a key role in the success of the analysis tool over the state-of-the-art analysis tools.
机译:对于当今无处不在的系统而言,访问控制变得越来越重要,该系统提供了防止敏感资源遭受未授权用户攻击的机制。在访问控制模型中,访问控制策略的管理是一项重要任务,它引起了关键的分析问题:如果一组管理员可以授予用户未授权的访问权限。在本文中,我们考虑了基于管理角色的访问控制(ARBAC)(最广泛的管理模型之一)的上下文中的分析问题。我们描述了如何设计启发式方法,以使称为asaspXL的分析工具能够扩展以处理大型和复杂的ARBAC策略以及一系列分析问题。广泛的实验表明,与最新的分析工具相比,拟议的启发式方法在分析工具的成功中起着关键作用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号