首页> 外文学位 >Assurance Management Framework for Access Control Systems.
【24h】

Assurance Management Framework for Access Control Systems.

机译:访问控制系统的保证管理框架。

获取原文
获取原文并翻译 | 示例

摘要

Access control is one of the most fundamental security mechanisms used in the design and management of modern information systems. However, there still exists an open question on how formal access control models can be automatically analyzed and fully realized in secure system development. Furthermore, specifying and managing access control policies are often error-prone due to the lack of effective analysis mechanisms and tools.;In this dissertation, I present an Assurance Management Framework (AMF) that is designed to cope with various assurance management requirements from both access control system development and policy-based computing. On one hand, the AMF framework facilitates comprehensive analysis and thorough realization of formal access control models in secure system development. I demonstrate how this method can be applied to build role-based access control systems by adopting the NIST/ANSI RBAC standard as an underlying security model. On the other hand, the AMF framework ensures the correctness of access control policies in policy-based computing through automated reasoning techniques and anomaly management mechanisms. A systematic method is presented to formulate XACML in Answer Set Programming (ASP) that allows users to leverage off-the-shelf ASP solvers for a variety of analysis services. In addition, I introduce a novel anomaly management mechanism, along with a grid-based visualization approach, which enables systematic and effective detection and resolution of policy anomalies. I further evaluate the AMF framework through modeling and analyzing multiparty access control in Online Social Networks (OSNs). A MultiParty Access Control (MPAC) model is formulated to capture the essence of multiparty authorization requirements in OSNs. In particular, I show how AMF can be applied to OSNs for identifying and resolving privacy conflicts, and representing and reasoning about MPAC model and policy. To demonstrate the feasibility of the proposed methodology, a suite of proof-of-concept prototype systems is implemented as well.
机译:访问控制是现代信息系统的设计和管理中使用的最基本的安全机制之一。但是,关于如何在安全系统开发中如何自动分析并完全实现正式的访问控制模型仍存在一个未解决的问题。此外,由于缺乏有效的分析机制和工具,指定和管理访问控制策略通常容易出错。;在本文中,我提出了一种保证管理框架(AMF),该框架旨在满足双方的各种保证管理要求。访问控制系统开发和基于策略的计算。一方面,AMF框架有助于在安全系统开发中全面分析和全面实现正式的访问控制模型。我将演示如何通过采用NIST / ANSI RBAC标准作为基础安全模型来将该方法应用于构建基于角色的访问控制系统。另一方面,AMF框架通过自动推理技术和异常管理机制确保基于策略的计算中访问控制策略的正确性。提出了一种系统化的方法来制定答案集编程(ASP)中的XACML,该方法使用户可以利用现成的ASP求解器来提供各种分析服务。此外,我介绍了一种新颖的异常管理机制,以及基于网格的可视化方法,该方法可以系统有效地检测和解决策略异常。我将通过对在线社交网络(OSN)中的多方访问控制进行建模和分析,进一步评估AMF框架。制定了多方访问控制(MPAC)模型以捕获OSN中多方授权要求的本质。特别是,我展示了如何将AMF应用于OSN来识别和解决隐私冲突,以及表示和推理MPAC模型和策略。为了证明所提出方法的可行性,还实施了一套概念验证原型系统。

著录项

  • 作者

    Hu, Hongxin.;

  • 作者单位

    Arizona State University.;

  • 授予单位 Arizona State University.;
  • 学科 Computer Science.
  • 学位 Ph.D.
  • 年度 2012
  • 页码 181 p.
  • 总页数 181
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号