Towards Continuous Access Control Validation and Forensics

Towards Continuous Access Control Validation and Forensics
复制标题

DOI:
10.1145/3319535.3363191
复制
发表时间:
2019-11
期刊:
Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Chengcheng Xiang;Yudong Wu;Bingyu Shen;Mingyao Shen;Haochen Huang;Tianyin Xu;Yuanyuan Zhou;Cindy Moore;Xinxin Jin;Tianwei Sheng
Chengcheng Xiang;Yudong Wu;Bingyu Shen;Mingyao Shen;Haochen Huang;Tianyin Xu;Yuanyuan Zhou;Cindy Moore;Xinxin Jin;Tianwei Sheng
中科院分区:
其他
文献类型:
--
作者:
Chengcheng Xiang;Yudong Wu;Bingyu Shen;Mingyao Shen;Haochen Huang;Tianyin Xu;Yuanyuan Zhou;Cindy Moore;Xinxin Jin;Tianwei Sheng

文献摘要

被引文献

相似文献

在实际实践中,由于系统管理员(系统管理员)引入的普遍策略错误配置,访问控制经常被报告为“严重中断”。考虑到资源和数据共享的动态变化,访问控制策略需要不断更新。不幸的是,人类系统管理员经常犯错误,比如在更改访问控制策略时过度授予权限。由于目前对持续验证的工具支持有限,这样的错误可能会在很长一段时间内不被注意到,直到最终被攻击者利用,导致灾难性的安全事件。提出了一种实用的访问控制行为监控工具P-Diff,以帮助系统管理员及早发现意外的访问控制策略变化,并对安全攻击进行事后取证分析。P-DIFF持续监控访问日志,并从中推断访问控制策略。为了应对策略演化的挑战,我们设计了一种新的时变决策树来有效地表示访问控制策略的变化,并结合了一种新的学习算法来从访问日志中推断树。P-DIFF为系统管理员提供推断的策略和检测到的更改,以帮助完成以下两个任务:(1)验证访问控制更改是否是有意的;(2)确定导致给定安全攻击的历史更改。我们使用从五个真实世界系统收集的各种数据集来评估P-DIFF,其中包括两个来自工业公司的数据集。P-DIFF能够检测86%-100%的访问控制策略变化,平均准确率为%。对于法医分析,P-DIFF可以在85%-98%的评估案例中精确定位允许目标访问的根本原因变化。
Access control is often reported to be "profoundly broken" in real-world practices due to prevalent policy misconfigurations introduced by system administrators (sysadmins). Given the dynamics of resource and data sharing, access control policies need to be continuously updated. Unfortunately, to err is human-sysadmins often make mistakes such as over-granting privileges when changing access control policies. With today's limited tooling support for continuous validation, such mistakes can stay unnoticed for a long time until eventually being exploited by attackers, causing catastrophic security incidents. We present P-DIFF, a practical tool for monitoring access control behavior to help sysadmins early detect unintended access control policy changes and perform postmortem forensic analysis upon security attacks. P-DIFF continuously monitors access logs and infers access control policies from them. To handle the challenge of policy evolution, we devise a novel time-changing decision tree to effectively represent access control policy changes, coupled with a new learning algorithm to infer the tree from access logs. P-DIFF provides sysadmins with the inferred policies and detected changes to assist the following two tasks: (1) validating whether the access control changes are intended or not; (2) pinpointing the historical changes responsible for a given security attack. We evaluate P-DIFF with a variety of datasets collected from five real-world systems, including two from industrial companies. P-DIFF can detect 86%-100% of access control policy changes with an average precision of 89%. For forensic analysis, P-DIFF can pinpoint the root-cause change that permits the target access in 85%-98% of the evaluated cases.