Expressions of expertness

Expressions of expertness
复制标题

专业的表达

DOI:
10.1145/1408664.1408675
复制
发表时间:
2008
期刊:
--
影响因子:
--
通讯作者:
Inglesant P
Inglesant P
中科院分区:
--
文献类型:
--
作者:
Inglesant P

文献摘要

相似文献

在日益增长的网格计算领域,实现可用的安全尤其具有挑战性,在网格计算领域,控制是分散的,系统是异质的,授权应用于跨管理域。基于角色的访问控制(Role-Based Access Control,RBAC)模型的PERMIS提供了一个统一的基础设施来应对这些挑战。以前的研究发现,不理解Permis RBAC模型的资源所有者很难表达访问控制策略。我们已经通过调查使用受控自然语言解析器来表达这些策略来解决了这个问题。在本文中,我们描述了我们在为Permis编辑器设计、实现和评估该解析器方面的经验。我们首先通过与45名网格从业人员的访谈和焦点小组,了解资源所有者所表达的网格访问控制需求。我们发现,网格计算使用的许多领域都存在不同的安全需求;这建议使用最小的、开放的设计。我们设计并实现了一个支持这些需求的受控自然语言系统,并对17个目标用户进行了评估。我们发现,参与者并没有被文本编辑器吓倒,而且很容易理解语法。然而,对受控语言的一些严格要求是有问题的。使用受控自然语言有助于克服Permis RBAC和旧范例之间的一些概念不匹配;然而,仍然有一些微妙之处并不总是被理解。总而言之,解析器本身是不够的,应该在与permis编辑器的其他部分的交互中看到解析器,以便迭代地帮助用户理解底层的permis模型,并更准确、更完整地表达他们的安全策略。
The implementation of usable security is particularly challenging in the growing field of Grid computing, where control is decentralised, systems are heterogeneous, and authorization applies across administrative domains. PERMIS, based on the Role-Based Access Control (RBAC) model, provides a unified infrastructure to address these challenges. Previous research has found that resource owners who do not understand the PERMIS RBAC model have difficulty expressing access control policies. We have addressed this issue by investigating the use of a controlled natural language parser for expressing these policies. In this paper, we describe our experiences in the design, implementation, and evaluation of this parser for the PERMIS Editor. We began by understanding Grid access control needs as expressed by resource owners, through interviews and focus groups with 45 Grid practitioners. We found that the many areas of Grid computing use present varied security requirements; this suggests a minimal, open design. We designed and implemented a controlled natural language system to support these needs, which we evaluated with a cross-section of 17 target users. We found that participants were not daunted by the text editor, and understood the syntax easily. However, some strict requirements of the controlled language were problematic. Using controlled natural language helps overcome some conceptual mis-matches between PERMIS RBAC and older paradigms; however, there are still subtleties which are not always understood. In conclusion, the parser is not sufficient on its own, and should be seen in the interplay with other parts of the PERMIS Editor, so that, iteratively, users are helped to understand the underlying PERMIS model and to express their security policies more accurately and more completely.