首页> 外文会议>International Conference on Avilability, Reliability and Security >Techniques for Automating Policy Specification for Application-oriented Access Controls
【24h】

Techniques for Automating Policy Specification for Application-oriented Access Controls

机译:以应用面向应用程序的访问控制自动化策略规范的技术

获取原文

摘要

By managing the authority assigned to each application, rule-based application-oriented access controls can significantly mitigate the threats posed by malicious code due to software vulnerabilities or malware. However, these policies are typically complex and difficult to develop. Learning modes can ease specification, however, they still require high levels of expertise to utilise correctly, and are most suited to confining non-malicious software. This paper presents a novel approach to automating policy specification for rule-based application-oriented access controls. The functionality-based application confinement (FBAC) model provides reusable parameterised abstractions. A number of straightforward yet effective techniques are presented that use these functionality-based abstractions to create application policies a priori, that is, without running programs before policies are specified. These techniques automate the specification of policy details by analysing program dependencies, program management information, and file system contents.
机译:通过管理分配给每个应用程序的权限,由于软件漏洞或恶意软件,基于规则的面向应用程序的访问控制可以显着减轻恶意代码所构成的威胁。但是,这些政策通常很复杂,难以发展。学习模式可以轻松规格,但是,它们仍然需要高水平的专业知识来利用正确,并且最适合限制非恶意软件。本文介绍了一种新颖的方法来自动化基于规则的应用面向应用的访问控制的策略规范。基于功能的应用程序限制(FBAC)模型提供可重用的参数化抽象。提出了许多简单但有效的技术,该技术使用基于这些功能的抽象来创建应用程序策略a先验,即在指定策略之前而不运行的程序。这些技术通过分析程序依赖性,程序管理信息和文件系统内容来自动化策略详细信息。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号