Quantitative Policy Repair for Access Control on the Cloud

Quantitative Policy Repair for Access Control on the Cloud
复制标题

云上访问控制的定量策略修复

DOI:
10.1145/3597926.3598078
复制
发表时间:
2023
期刊:
ISSTA 2023
影响因子:
--
通讯作者:
Bultan, Tevfik
Bultan, Tevfik
中科院分区:
--
文献类型:
--
作者:
Eiers, William;Sankaran, Ganesh;Bultan, Tevfik

文献摘要

参考文献

被引文献

相似文献

随着云计算的日益普及,提供对云中存储的信息的安全访问已成为一个关键问题。由于访问控制策略的复杂性,管理员可能会无意中允许对私人信息的意外访问,这是基于云的服务中数据泄露的常见来源。在本文中,我们提出了一种用于自动策略修复的定量符号分析方法,以修复过于宽松的策略。我们使用 SMT 公式对访问控制策略的语义进行编码,并使用模型计数评估其许可性。给定一个策略、一个许可边界和一组应该被允许的请求,我们通过减少和细化迭代地修复该策略,以便达到许可边界,同时仍然允许给定的一组请求。我们通过将自动策略修复技术应用于以 Amazon 的 AWS Identity and Access Management (IAM) 策略语言编写的策略来展示其有效性。
With the growing prevalence of cloud computing, providing secure access to information stored in the cloud has become a critical problem. Due to the complexity of access control policies, administrators may inadvertently allow unintended access to private information, and this is a common source of data breaches in cloud based services. In this paper, we present a quantitative symbolic analysis approach for automated policy repair in order to fix overly permissive policies. We encode the semantics of the access control policies using SMT formulas and assess their permissiveness using model counting. Given a policy, a permissiveness bound, and a set of requests that should be allowed, we iteratively repair the policy through permissiveness reduction and refinement, so that the permissiveness bound is reached while the given set of requests are still allowed. We demonstrate the effectiveness of our automated policy repair technique by applying it to policies written in Amazon's AWS Identity and Access Management (IAM) policy language.
DOI: 10.1145/234313.234412
发表时间: 1996-03-01
影响因子: 16.6
作者:
Sandhu, R;Samarati, P
通讯作者: Samarati, P
Quacky:定量访问控制许可分析仪➜±
DOI: 10.1145/3551349.3559530
发表时间: 2022
期刊: ASE 2022
影响因子: --
作者:
Eiers, William;Sankaran, Ganesh;Li, Albert;O'Mahony, Emily;Prince, Benjamin;Bultan, Tevfik
通讯作者: Bultan, Tevfik
DOI: 10.1109/sp.2010.36
发表时间: 2010-05
期刊: 2010 IEEE Symposium on Security and Privacy
影响因子: --
作者:
Leo A. Meyerovich;B. Livshits
通讯作者: Leo A. Meyerovich;B. Livshits
DOI: 10.1109/secpri.1997.601312
发表时间: 1997
期刊: Proceedings. 1997 IEEE Symposium on Security and Privacy (Cat. No.97CB36097)
影响因子: --
作者:
S. Jajodia;P. Samarati;V. S. Subrahmanian
通讯作者: V. S. Subrahmanian
DOI: --
发表时间: 1999
期刊:
影响因子: --
作者:
J. L. Abad;Hervé Debar;T. Schweinberger;P. Trommler
通讯作者: P. Trommler