...
首页> 外文期刊>International Journal of Information Security >Analyzing XACML policies using answer set programming
【24h】

Analyzing XACML policies using answer set programming

机译:使用答案集编程分析XACML策略

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

With the tremendous growth of Web applications and services, eXtensible Access Control Markup Language (XACML) has been broadly adopted to specify Web access control policies. However, when the policies are large or defined by multiple authorities, it has proved difficult to analyze errors and vulnerabilities in a manual fashion. Recent advances in the answer set programming (ASP) paradigm have provided a powerful problem-solving formalism that is capable of dealing with policy verification. In this paper, we employ ASP to analyze various properties of XACML policies. To this end, we first propose a structured mechanism to translate a XACML policy into an ASP program. Then, we leverage the features of off-the-shelf ASP solvers to specify and verify a wide range of properties of a XACML policy, including redundancy, conflicts, refinement, completeness, reachability, and usefulness. We present an empirical evaluation of the effectiveness and efficiency of a policy analysis tool implemented on top of the Clingo ASP solver. The evaluation results show that our approach is computationally more efficient compared with existing approaches.
机译:随着Web应用程序和服务的巨大增长,广泛采用可扩展访问控制标记语言(XACML)来指定Web访问控制策略。但是,当政策大或由多个当局定义时,它证明难以在手动时尚中分析错误和漏洞。答案集编程(ASP)范式的最新进展提供了一个强大的解决问题,可以解决能够处理政策验证。在本文中,我们使用ASP分析XACML政策的各种性质。为此,我们首先提出了一种结构化机制来将XACML策略转化为ASP程序。然后,我们利用了现成的ASP求解器的功能来指定和验证XACML策略的广泛属性,包括冗余,冲突,细化,完整性,可达性和有用性。我们介绍了在Clingo ASP求解器顶部实施的政策分析工具的有效性和效率的实证评价。评估结果表明,与现有方法相比,我们的方法与现有方法相比更有效。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号