Quantifying permissiveness of access control policies

Quantifying permissiveness of access control policies
复制标题

量化访问控制策略的允许性

DOI:
10.1145/3510003.3510233
复制
发表时间:
2022
期刊:
ICSE '22: Proceedings of the 44th International Conference on Software Engineering
影响因子:
--
通讯作者:
Bultan, Tevfik
Bultan, Tevfik
中科院分区:
--
文献类型:
--
作者:
Eiers, William;Sankaran, Ganesh;Li, Albert;O'Mahony, Emily;Prince, Benjamin;Bultan, Tevfik

文献摘要

相似文献

由于软件服务的普遍使用,保护存储在计算云中的私有信息的机密性正成为一个越来越关键的问题。虽然访问控制规范语言和库提供了保护信息机密性的机制,但如果没有可以帮助开发人员编写策略的验证和确认技术,复杂的策略规范可能会出现错误,导致对数据的意外和未经授权的访问,可能造成灾难性的后果。在本文中,我们提出了一个定量和差分政策分析框架,不仅确定一个政策是更宽容的比另一个政策,但也量化的访问控制政策的相对宽容。我们量化许可的政策使用模型计数约束求解器。我们提出了一种启发式算法,可以转换从访问控制策略中提取的约束,并显着提高模型计数性能。我们通过将其应用于以Amazon的AWS Identity and Access Management(IAM)策略语言和Microsoft的Azure策略语言编写的策略来证明我们方法的有效性。
Due to ubiquitous use of software services, protecting the confidentiality of private information stored in compute clouds is becoming an increasingly critical problem. Although access control specification languages and libraries provide mechanisms for protecting confidentiality of information, without verification and validation techniques that can assist developers in writing policies, complex policy specifications are likely to have errors that can lead to unintended and unauthorized access to data, possibly with disastrous consequences. In this paper, we present a quantitative and differential policy analysis framework that not only identifies if one policy is more permissive than another policy, but also quantifies the relative permissiveness of access control policies. We quantify permissiveness of policies using a model counting constraint solver. We present a heuristic that transforms constraints extracted from access control policies and significantly improves the model counting performance. We demonstrate the effectiveness of our approach by applying it to policies written in Amazon's AWS Identity and Access Management (IAM) policy language and Microsoft's Azure policy language.