Modeling adaptive access control policies using answer set programming

Modeling adaptive access control policies using answer set programming
复制标题

使用答案集编程对自适应访问控制策略进行建模

DOI:
10.1016/j.jisa.2018.10.007
复制
发表时间:
2019
影响因子:
5.6
通讯作者:
Namin, Akbar Siami
Namin, Akbar Siami
中科院分区:
计算机科学3区
文献类型:
--
作者:
Sartoli, Sara;Namin, Akbar Siami

文献摘要

参考文献

被引文献

相似文献

许多现有的管理平台,如普适计算系统实现的政策,依赖于动态的操作环境的变化。用于自动实施访问控制策略的现有形式方法主要以常规逻辑编程(也称为单调逻辑)来表达,例如,一阶逻辑(FOL)单调逻辑的主要问题是,它们不是为了根据进一步的观察使最初的信念无效而设计的。这种限制使得这些传统的逻辑方法不太适合建模和分析上下文感知的访问控制策略,其中异常策略在运行时增量和自适应地引入。当需要强制执行异常时,无法使初始策略无效可能会导致需要由人工实体手动解决的不一致和违规。为了解决传统的逻辑方法的问题,更重要的是防止这种不一致,本文提出了一种非单调的基于逻辑的推理方案建模和分析自适应访问控制策略。在所提出的形式主义,不可用的上下文数据和不完整的访问控制策略可以明确地表示。为此,本文区分了三种策略:默认策略、上下文相关策略和例外策略。建议的形式主义是基于回答集编程(ASP),一个非单调的逻辑编程语言,允许优雅的表示不可用的上下文数据在自适应系统。我们设计了非单调策略推理规则,以便在定义异常策略时,它们自动优先于默认策略和上下文相关策略。两个案例研究的结果报告,以证明所提出的政策表示方案的可行性相比,基于语义的访问控制(OrBAC)模型。
Many of the existing management platforms such as pervasive computing systems implement policies that depend on dynamic operational environment changes. Existing formal approaches for automatically enforcing access control policies are primarily expressed in conventional logic programming, also known as monotonic logics, e.g., First Order Logic (FOL). The major issue with monotonic logics is that they are not devised to invalidate initial believes in the light of further observations. This limitation makes these traditional logical approaches less suitable for modeling and analyzing context-aware access control policies, where exceptional policies are introduced incrementally and adaptively during runtime. The inability to invalidate initial policies when an exception needs to be enforced might result in inconsistencies and violations that need to be resolved manually by human entities. To address the problems with conventional logical approaches and more importantly prevent such inconsistencies, this paper presents a non-monotonic logic-based reasoning scheme for modeling and analyzing adaptive access control policies. In the proposed formalism, unavailable context data and incomplete access control policies can be explicitly expressed. To do so, the paper distinguishes three kinds of policies: default, context-dependent and exception policies. The proposed formalism is based on Answer Set Programming (ASP), a non-monotonic logic programming language that allows elegant representation of unavailability of context data in adaptive systems. We devise non-monotonic policy inference rules such that, when exception policies are defined, they take precedence over default and context-dependent policies automatically. The results of two case studies are reported to demonstrate the feasibility of the proposed policy representation scheme compared to the Organizational-Based Access Control (OrBAC) model.
DOI: 10.1145/3243734.3278489
发表时间: 2018-10
期刊: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
Jianjun Zheng;A. Namin
通讯作者: Jianjun Zheng;A. Namin
高级访问控制模型中的高级冲突管理策略
DOI: --
发表时间: 2007
期刊: ICS@SYNASC
影响因子: --
作者:
F. Cuppens;N. Cuppens;Meriam Ben
通讯作者: Meriam Ben
关于访问控制中的缺失属性:非确定性和概率性属性检索
DOI: --
发表时间: 2015
期刊: ACM Symposium on Access Control Models and Technologies
影响因子: --
作者:
J. Crampton;C. Morisset;Nicola Zannone
通讯作者: Nicola Zannone
使用 ASP 分析 XACML 策略
DOI: --
发表时间: 2015
期刊: International Conference on New Technologies, Mobility and Security
影响因子: --
作者:
D. Ayed;Marie;Cyrille Martins
通讯作者: Cyrille Martins
STS-工具:通过社会承诺实现社会技术安全要求
DOI: --
发表时间: 2012
期刊: IEEE International Requirements Engineering Conference
影响因子: --
作者:
Elda Paja;F. Dalpiaz;Mauro Poggianella;Pierluigi Roberti;P. Giorgini
通讯作者: P. Giorgini