首页> 外文学位 >Incremental analysis of Role Based Access Control policies.
【24h】

Incremental analysis of Role Based Access Control policies.

机译:基于角色的访问控制策略的增量分析。

获取原文
获取原文并翻译 | 示例

摘要

Role-Based Access Control (RBAC) is a widely used model for expressing access control policies. In large organizations, the RBAC policies may be collectively managed by many administrators. Administrative RBAC (ARBAC) is a model for expressing the authority of administrators, thereby specifying how an organization's RBAC policy may change. Changes by one administrator may interact in unintended ways with changes by other administrators. Consequently, the effect of the RBAC and ARBAC policies is hard to understand by simple inspection. Policy analysis helps system designers and administrators understand RBAC and ARBAC policies by answering questions (queries) about them.;Both RBAC and ARBAC policies tend to evolve over time. Changes to these policies may violate certain safety properties. Incremental computation is useful in situation where small changes to the policy lead to small or no changes in the analysis results. In limiting cases, a complete reanalysis cannot be avoided, but in many cases, the results of the previous analysis may be reused to update the analysis more quickly than a complete re-evaluation. In this thesis, we consider the problem of incremental analysis of RBAC and ARBAC policies, in particular to determine the information flow implied by the RBAC policies and the reachability properties of ARBAC policies. Our experimental data show that our incremental algorithms perform significantly better than the non-incremental algorithms.
机译:基于角色的访问控制(RBAC)是表达访问控制策略的一种广泛使用的模型。在大型组织中,RBAC策略可能由许多管理员共同管理。管理RBAC(ARBAC)是用于表达管理员权限的模型,从而指定了组织的RBAC策略可能如何更改。一个管理员的更改可能会与其他管理员的更改以意外方式交互。因此,通过简单的检查很难理解RBAC和ARBAC政策的效果。策略分析通过回答有关它们的问题(查询),可以帮助系统设计人员和管理员了解RBAC和ARBAC策略。RBAC和ARBAC策略都倾向于随着时间而发展。更改这些政策可能会违反某些安全属性。增量计算在策略的较小更改导致分析结果较小或没有更改的情况下很有用。在有限的情况下,无法避免进行完整的重新分析,但是在许多情况下,与完整的重新评估相比,以前的分析结果可以重新使用以更快地更新分析。本文考虑了RBAC和ARBAC策略的增量分析问题,特别是确定RBAC策略隐含的信息流和ARBAC策略的可达性。我们的实验数据表明,增量算法的性能明显优于非增量算法。

著录项

  • 作者

    He, Jian.;

  • 作者单位

    State University of New York at Binghamton.;

  • 授予单位 State University of New York at Binghamton.;
  • 学科 Computer Science.
  • 学位 M.S.
  • 年度 2008
  • 页码 74 p.
  • 总页数 74
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 自动化技术、计算机技术;
  • 关键词

  • 入库时间 2022-08-17 11:38:51

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号