Expressions of expertness: the virtuous circle of natural language for access control policy specification

Expressions of expertness: the virtuous circle of natural language for access control policy specification
复制标题

专业表达:访问控制策略规范的自然语言良性循环

DOI:
--
复制
发表时间:
2008
期刊:
Symposium On Usable Privacy and Security
影响因子:
--
通讯作者:
Lei Lei Shi
Lei Lei Shi
中科院分区:
--
文献类型:
--
作者:
P. Inglesant;M. Sasse;D. Chadwick;Lei Lei Shi

文献摘要

参考文献

被引文献

相似文献

在不断发展的网格计算领域,可用的安全性的实现尤其具有挑战性,在网格计算中,控制是分散的,系统是异构的,并且授权适用于跨管理域。基于角色访问控制(RBAC)模型的PERMIS提供了一个统一的基础设施来解决这些挑战。以前的研究发现,不理解PERMIS RBAC模型的资源所有者很难表达访问控制策略。我们已经解决了这个问题,通过调查使用一个控制的自然语言解析器来表达这些政策。在本文中,我们描述了我们的经验,在设计,实现和评估这个分析器的PERMIS编辑器。我们开始了解网格访问控制的需求所表示的资源所有者,通过访谈和焦点小组与45网格从业者。我们发现,网格计算的许多领域都有不同的安全需求,这表明它是一个最小的、开放的设计。我们设计并实现了一个可控的自然语言系统来支持这些需求,我们评估了17个目标用户的横截面。我们发现,参与者并没有被文本编辑器吓倒,并且很容易理解语法。然而,对受控语言的一些严格要求是有问题的。使用受控的自然语言有助于克服PERMIS RBAC和旧范式之间的一些概念上的不匹配;然而,仍然有一些微妙之处并不总是被理解。总之,解析器本身是不够的,应该在与PERMIS编辑器的其他部分的相互作用中看到,以便迭代地帮助用户理解底层PERMIS模型,并更准确和更完整地表达他们的安全策略。
The implementation of usable security is particularly challenging in the growing field of Grid computing, where control is decentralised, systems are heterogeneous, and authorization applies across administrative domains. PERMIS, based on the Role-Based Access Control (RBAC) model, provides a unified infrastructure to address these challenges. Previous research has found that resource owners who do not understand the PERMIS RBAC model have difficulty expressing access control policies. We have addressed this issue by investigating the use of a controlled natural language parser for expressing these policies. In this paper, we describe our experiences in the design, implementation, and evaluation of this parser for the PERMIS Editor. We began by understanding Grid access control needs as expressed by resource owners, through interviews and focus groups with 45 Grid practitioners. We found that the many areas of Grid computing use present varied security requirements; this suggests a minimal, open design. We designed and implemented a controlled natural language system to support these needs, which we evaluated with a cross-section of 17 target users. We found that participants were not daunted by the text editor, and understood the syntax easily. However, some strict requirements of the controlled language were problematic. Using controlled natural language helps overcome some conceptual mis-matches between PERMIS RBAC and older paradigms; however, there are still subtleties which are not always understood. In conclusion, the parser is not sufficient on its own, and should be seen in the interplay with other parts of the PERMIS Editor, so that, iteratively, users are helped to understand the underlying PERMIS model and to express their security policies more accurately and more completely.
DOI: --
发表时间: --
期刊: --
影响因子: --
作者:
David Chadwick (Author)
通讯作者: David Chadwick (Author)