Managing access control policies using access control spaces

Managing access control policies using access control spaces
复制标题

使用访问控制空间管理访问控制策略

DOI:
--
复制
发表时间:
2002
期刊:
ACM Symposium on Access Control Models and Technologies
影响因子:
--
通讯作者:
Xiaolan Zhang
Xiaolan Zhang
中科院分区:
--
文献类型:
--
作者:
T. Jaeger;A. Edwards;Xiaolan Zhang

文献摘要

被引文献

相似文献

我们介绍了访问控制空间的概念,并研究了它在管理访问控制策略方面的有用。访问控制空间代表主题的权限分配状态。我们确定具有有意义语义的子空间。例如,明确分配给主题的集合权限定义了其指定的子空间,并约束定义了禁止的子空间。在分析这些子空间时,我们确定了两个问题:(1)通常,访问控制空间的很大一部分具有未知的分配语义,这意味着它尚未定义该空间中的分配是否允许,并且(2)通常易于理解的高级任务和约束导致在指定和禁止权限的情况下发生冲突。为了解决这些问题,我们开发了一种称为Gokyo的工具,该工具可以对访问控制空间进行定义和分析。 Gokyo计算未知子空间,以向系统管理员显示模棱两可的区域,并使他们减少它。 Gokyo确定了相互矛盾的子空间,并使系统管理员可以将子空间处理为例外(如果需要)。我们通过分析Web服务器策略示例来演示Gokyo的实用性。
We present the concept of an access control space and investigate how it may be useful in managing access control policies. An access control space represents the permission assignment state of a subject. We identify subspaces that have meaningful semantics. For example, the set permissions explicitly assigned to a subject defines its specified subspace, and constraints define the prohibited subspace. In analyzing these subspaces, we identify two problems: (1) often a significant portion of the access control space has unknown assignment semantics, meaning that it is not defined whether an assignment in this space should be permitted or not, and (2) often high-level assignments and constraints that are easily understood result in conflicts where permissions are both specified and prohibited. To solve these problems, we have developed a tool, called Gokyo, that enables definition and analysis of access control spaces. Gokyo computes the unknown subspace to show system administrators the ambiguous region and enable them to reduce it. Gokyo identifies conflicting subspaces and enables system administrators to handle subspaces as exceptions, if desired. We demonstrate the utility of Gokyo by analyzing a web server policy example.