Vac - Verifier of Administrative Role-Based Access Control Policies

Vac - Verifier of Administrative Role-Based Access Control Policies
复制标题

Vac - 基于管理角色的访问控制策略的验证器

DOI:
--
复制
发表时间:
2014
期刊:
International Conference on Computer Aided Verification
影响因子:
--
通讯作者:
G. Parlato
G. Parlato
中科院分区:
--
文献类型:
--
作者:
A. L. Ferrara;P. Madhusudan;Truc L. Nguyen;G. Parlato

文献摘要

参考文献

被引文献

相似文献

在本文中,我们提出了Vac,一个自动工具,用于验证安全属性的管理基于角色的访问控制(RBAC)。RBAC已经成为一种越来越流行的访问控制模型,特别适用于大型组织,并且在一些软件中实现。管理型RBAC系统的自动安全性分析是一个重要的研究课题,分析工具可以帮助设计者检查其策略是否满足预期的安全特性。Vac将管理RBAC策略转换为命令式程序,该命令式程序精确且抽象地模拟策略,并支持多个自动验证后端来分析结果程序。在本文中,我们描述了Vac的体系结构,并概述了已实施的工具中的分析技术。我们还报告了几个基准从文献中的实验。
In this paper we present Vac, an automatic tool for verifying security properties of administrative Role-based Access Control (RBAC). RBAC has become an increasingly popular access control model, particularly suitable for large organizations, and it is implemented in several software. Automatic security analysis of administrative RBAC systems is recognized as an important problem, as an analysis tool can help designers check whether their policies meet expected security properties. Vac converts administrative RBAC policies to imperative programs that simulate the policies both precisely and abstractly and supports several automatic verification back-ends to analyze the resulting programs. In this paper, we describe the architecture of Vac and overview the analysis techniques that have been implemented in the tool. We also report on experiments with several benchmarks from the literature.
安全与信任管理
DOI: 10.1007/978-3-319-24858-5_2
发表时间: 2015
期刊: --
影响因子: --
作者:
Lavygina A
通讯作者: Lavygina A
HSF(C):基于 Horn Clauses 的软件验证器 -(竞赛贡献)
DOI: 10.1007/978-3-642-28756-5_46
发表时间: 2012
期刊:
影响因子: --
作者:
Sergey Grebenshchikov;Ashutosh Gupta;Nuno P. Lopes;Corneliu Popeea;Andrey Rybalchenko
通讯作者: Andrey Rybalchenko