Anomaly discovery and resolution in web access control policies

Anomaly discovery and resolution in web access control policies
复制标题

DOI:
10.1145/1998441.1998472
复制
发表时间:
2011-06
期刊:
--
影响因子:
--
通讯作者:
Hongxin Hu;Gail-Joon Ahn;Ketan Kulkarni
Hongxin Hu;Gail-Joon Ahn;Ketan Kulkarni
中科院分区:
其他
文献类型:
--
作者:
Hongxin Hu;Gail-Joon Ahn;Ketan Kulkarni

文献摘要

被引文献

相似文献

Web服务、面向服务的体系结构和云计算等新兴技术的出现使我们能够更高效地执行业务服务。然而,在通过这样的前沿技术增长为互联网用户提供更便捷的服务的同时,我们仍然遭受着商业服务中未经授权的行为造成的意外安全泄漏。此外,由于缺乏有效的分析机制和工具,设计和管理Web访问控制策略往往容易出错。本文提出了一种新颖的Web访问控制策略异常分析方法。我们关注XACML(eXtensible Access Control Markup Language,可扩展访问控制标记语言)策略,因为XACML已经成为为各种基于Web的应用程序和服务指定和实施访问控制策略的事实标准。我们引入了一种基于策略的分割技术来准确地识别策略异常并得出有效的异常解决方案。我们还讨论了我们的方法XAnalyzer的概念验证实现,并演示了我们的方法如何高效地发现和解决策略异常。
The advent of emerging technologies such as Web services, service-oriented architecture, and cloud computing has enabled us to perform business services more efficiently and effectively. However, we still suffer from unintended security leakages by unauthorized actions in business services while providing more convenient services to Internet users through such a cutting-edge technological growth. Furthermore, designing and managing Web access control policies are often error-prone due to the lack of effective analysis mechanisms and tools. In this paper, we represent an innovative policy anomaly analysis approach for Web access control policies. We focus on XACML (eXtensible Access Control Markup Language) policy since XACML has become the de facto standard for specifying and enforcing access control policies for various Web-based applications and services. We introduce a policy-based segmentation technique to accurately identify policy anomalies and derive effective anomaly resolutions. We also discuss a proof-of-concept implementation of our method called XAnalyzer and demonstrate how efficiently our approach can discover and resolve policy anomalies.