首页> 外文OA文献 >Vac - Verifier of Administrative Role-Based Access Control Policies.
【2h】

Vac - Verifier of Administrative Role-Based Access Control Policies.

机译:Vac-基于管理角色的访问控制策略的验证者。

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

In this paper we present Vac, an automatic tool for verifying security properties of administrative Role-based Access Control (RBAC). RBAC has become an increasingly popular access control model, particularly suitable for large organizations, and it is implemented in several software. Automatic security analysis of administrative RBAC systems is recognized as an important problem, as an analysis tool can help designers check whether their policies meet expected security properties. Vac converts administrative RBAC policies to imperative programs that simulate the policies both precisely and abstractly and supports several automatic verification back-ends to analyze the resulting programs. In this paper, we describe the architecture of Vac and overview the analysis techniques that have been implemented in the tool. We also report on experiments with several benchmarks from the literature.
机译:在本文中,我们介绍了Vac,这是一种用于验证基于角色的管理访问控制(RBAC)安全属性的自动工具。 RBAC已成为一种越来越流行的访问控制模型,特别适用于大型组织,并且已在多种软件中实现。管理RBAC系统的自动安全性分析被认为是一个重要问题,因为分析工具可以帮助设计人员检查其策略是否符合预期的安全性。 Vac将管理性RBAC策略转换为命令式程序,该命令式程序可以精确抽象地模拟策略,并支持多个自动验证后端以分析生成的程序。在本文中,我们描述了Vac的体系结构,并概述了该工具中已实现的分析技术。我们还报告了文献中使用多个基准进行的实验。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号