Automated Inference of Access Control Policies for Web Applications

Automated Inference of Access Control Policies for Web Applications
复制标题

自动推断 Web 应用程序的访问控制策略

DOI:
--
复制
发表时间:
2015
期刊:
ACM Symposium on Access Control Models and Technologies
影响因子:
--
通讯作者:
Benjamin Hourte
Benjamin Hourte
中科院分区:
--
文献类型:
--
作者:
H. Le;Duy Cu Nguyen;L. Briand;Benjamin Hourte

文献摘要

被引文献

相似文献

在本文中,我们提出了一种新的,半自动化的方法来推断访问控制策略自动基于Web的应用程序。我们的目标是支持对已实现的访问控制策略进行验证,即使这些策略尚未明确指定或记录。我们使用基于角色的访问控制作为参考模型。建立在一套安全工具之上,我们的方法自动运行测试中的系统,并为一组已知的用户和角色构建访问空间。然后,我们应用机器学习技术来推断访问规则。然后分析不一致的规则,并将其反馈给流程,以进行进一步的测试和改进。最后,可以基于预先指定的规则(如果存在)来验证推断的规则。否则,将推断出的规则呈现给人类专家进行验证和检测访问控制问题。我们已经在两个应用程序上评估了我们的方法;一个是开源的,另一个是由我们的行业合作伙伴构建的专有系统。所获得的结果是非常有前途的推断规则的质量和访问控制漏洞,它有助于检测。
In this paper, we present a novel, semi-automated approach to infer access control policies automatically for web-based applications. Our goal is to support the validation of implemented access control policies, even when they have not been clearly specified or documented. We use role-based access control as a reference model. Built on top of a suite of security tools, our approach automatically exercises a system under test and builds access spaces for a set of known users and roles. Then, we apply a machine learning technique to infer access rules. Inconsistent rules are then analysed and fed back to the process for further testing and improvement. Finally, the inferred rules can be validated based on pre-specified rules if they exist. Otherwise, the inferred rules are presented to human experts for validation and for detecting access control issues. We have evaluated our approach on two applications; one is open source while the other is a proprietary system built by our industry partner. The obtained results are very promising in terms of the quality of inferred rules and the access control vulnerabilities it helped detect.