Auditing Workflow Executions against Dataflow Policies
Auditing Workflow Executions against Dataflow Policies
复制标题
根据数据流策略审核工作流执行
DOI:
--
复制
发表时间:
2010
期刊:
影响因子:
--
通讯作者:
Claus Wonnemann
中科院分区:
文献类型:
--
作者:
R. Accorsi;Claus Wonnemann
This paper presents IFAudit , an approach for the audit of dataflow policies in workflow models. IFAudit encompasses three steps. First, propagation graphs are generated from workflows’ log data. They represent the explicit information flows caused, e.g., by data access and message-passing, that have occurred during the execution of the workflow. Second, dataflow policies expressing security and compliance requirements are formalized in a system-independent manner as a binary relation on the workflow principals. Third, an audit algorithm analyzes the propagation graphs against the policies and delivers evidence with regard to whether the workflow complies with them. Besides presenting the corresponding algorithms, the paper discusses possible extensions to address more general types of information flows.