Quantitative Policy Repair for Access Control on the Cloud
Quantitative Policy Repair for Access Control on the Cloud
复制标题
云上访问控制的定量策略修复
DOI:
10.1145/3597926.3598078
复制
发表时间:
2023
期刊:
影响因子:
--
通讯作者:
Bultan, Tevfik
中科院分区:
文献类型:
--
作者:
Eiers, William;Sankaran, Ganesh;Bultan, Tevfik
With the growing prevalence of cloud computing, providing secure access to information stored in the cloud has become a critical problem. Due to the complexity of access control policies, administrators may inadvertently allow unintended access to private information, and this is a common source of data breaches in cloud based services. In this paper, we present a quantitative symbolic analysis approach for automated policy repair in order to fix overly permissive policies. We encode the semantics of the access control policies using SMT formulas and assess their permissiveness using model counting. Given a policy, a permissiveness bound, and a set of requests that should be allowed, we iteratively repair the policy through permissiveness reduction and refinement, so that the permissiveness bound is reached while the given set of requests are still allowed. We demonstrate the effectiveness of our automated policy repair technique by applying it to policies written in Amazon's AWS Identity and Access Management (IAM) policy language.
登录
查看更多内容
影响因子:
16.6
作者:
Sandhu, R;Samarati, P
通讯作者:
Samarati, P
DOI:
10.1145/3551349.3559530
发表时间:
2022
期刊:
ASE 2022
影响因子:
--
作者:
Eiers, William;Sankaran, Ganesh;Li, Albert;O'Mahony, Emily;Prince, Benjamin;Bultan, Tevfik
通讯作者:
Bultan, Tevfik
DOI:
10.1109/sp.2010.36
发表时间:
2010-05
期刊:
2010 IEEE Symposium on Security and Privacy
影响因子:
--
作者:
Leo A. Meyerovich;B. Livshits
通讯作者:
Leo A. Meyerovich;B. Livshits
DOI:
10.1109/secpri.1997.601312
发表时间:
1997
期刊:
Proceedings. 1997 IEEE Symposium on Security and Privacy (Cat. No.97CB36097)
影响因子:
--
作者:
S. Jajodia;P. Samarati;V. S. Subrahmanian
通讯作者:
V. S. Subrahmanian
DOI:
--
发表时间:
1999
期刊:
影响因子:
--
作者:
J. L. Abad;Hervé Debar;T. Schweinberger;P. Trommler
通讯作者:
P. Trommler