Quacky: Quantitative Access Control Permissiveness Analyzer✱

Quacky: Quantitative Access Control Permissiveness Analyzer✱
复制标题

Quacky:定量访问控制许可分析仪➜±

DOI:
10.1145/3551349.3559530
复制
发表时间:
2022
期刊:
ASE 2022
影响因子:
--
通讯作者:
Bultan, Tevfik
Bultan, Tevfik
中科院分区:
--
文献类型:
--
作者:
Eiers, William;Sankaran, Ganesh;Li, Albert;O'Mahony, Emily;Prince, Benjamin;Bultan, Tevfik

文献摘要

被引文献

相似文献

quacky 是一种用于量化云中访问控制策略许可性的工具。给定一个策略,quacky 将其转换为 SMT 公式,并使用模型计数约束求解器来量化许可性。当给定多个策略时,quacky 不仅确定哪个策略更宽松,而且还量化了策略之间的相对宽松程度。借助 quacky,政策制定者可以自动分析复杂的政策,帮助他们确保私人数据不会被意外访问。 quacky 支持以 Amazon Web Services (AWS) Identity and Access Management (IAM)、Microsoft Azure 和 Google Cloud Platform (GCP) 策略语言编写的访问控制策略。它具有命令行和 Web 界面。它是开源的,可从 https://github.com/vlab-cs-ucsb/quacky 获取。视频 URL:https://youtu.be/YsiGOI_SCtg。
quacky is a tool for quantifying permissiveness of access control policies in the cloud. Given a policy, quacky translates it into a SMT formula and uses a model counting constraint solver to quantify permissiveness. When given multiple policies, quacky not only determines which policy is more permissive, but also quantifies the relative permissiveness between the policies. With quacky, policy authors can automatically analyze complex policies, helping them ensure that there is no unintended access to private data. quacky supports access control policies written in the Amazon Web Services (AWS) Identity and Access Management (IAM), Microsoft Azure, and Google Cloud Platform (GCP) policy languages. It has command-line and web interfaces. It is open-source and available at https://github.com/vlab-cs-ucsb/quacky.Video URL: https://youtu.be/YsiGOI_SCtg.