首页> 外文会议>International Conference on Security and Management >Improving Transaction Success Rate by Detecting and Correcting Access Control Misconfigurations
【24h】

Improving Transaction Success Rate by Detecting and Correcting Access Control Misconfigurations

机译:通过检测和纠正访问控制误导性来提高交易成功率

获取原文

摘要

Security and availability are often contradictory goals to achieve in large organizations. In the context of databases, if too conservative access control policies are adopted, a large number of transactions are likely to be rejected due to inadequate user privileges. On the other hand, a liberal access control policy violates the principle of least privilege. However, it is impractical for a system administrator to correctly assign privileges to a large set of resources to a large number of users. In this paper, we attempt to achieve both the above goals by automatically detecting and correcting any access control misconfigurations. Using historical transaction data, we build associations between user-object, user-user, and object-object. The information so derived is used to handle any transactions that have been denied access due to misconfigurations.
机译:安全性和可用性通常是在大型组织中实现的矛盾目标。在数据库的上下文中,如果采用过于保守的访问控制策略,则由于用户权限不足,可能会拒绝大量事务。另一方面,自由主义访问控制政策违反了最不特权的原则。但是,系统管理员无法将权限分配给大量用户的大量资源是不切实际的。在本文中,我们试图通过自动检测和纠正任何访问控制错误配置来实现以上目标。使用历史事务数据,我们在用户对象,用户用户和对象之间构建关联。如此导出的信息用于处理由于错误配置而被拒绝访问的任何事务。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号