Access Control Policy Analysis and Visualization Tools for Security Professionals

Access Control Policy Analysis and Visualization Tools for Security Professionals
复制标题

面向安全专业人员的访问控制策略分析和可视化工具

DOI:
--
复制
发表时间:
2008
期刊:
影响因子:
--
通讯作者:
E. Bertino
E. Bertino
中科院分区:
--
文献类型:
--
作者:
Kami Vaniea;Qun Ni;L. Cranor;E. Bertino

文献摘要

被引文献

相似文献

对于安全管理员来说,管理大量访问控制规则是一项复杂的任务。规则的每次添加、删除或修改都会导致许多潜在的和未知的副作用,从规则冲突到安全漏洞。安全研究人员试图通过提出算法和工具来缓解这个问题,这些算法和工具可以分析规则列表,并向管理员提供更好地管理规则所需的信息。不幸的是,这些分析工具很少能将政策问题与问题根源清楚地联系起来。在这项工作中,我们讨论一个界面,该界面可以根据规则列表可视化策略分析的输出和输出源,并向管理员显示其更改的效果。
Managing large sets of access-control rules is a complex task for security administrators. Each addition, deletion or modification of a rule causes many potential and unknown side effects ranging from rule conflicts to security breaches. Security researchers have attempted to alleviate this problem by proposing algorithms and tools which analyze lists of rules and provide administrators with the information that they need to better manage their rules. Unfortunately few of these analysis tools connect a policy problem to the source of the problem clearly. In this work we discuss an interface that visualizes the output of policy analysis and the source of the output in terms of rule lists and shows administrators the effect of their changes.