TC:Medium: Collaborative Research: Towards Formal, Risk Aware Authorization

TC:中:协作研究:迈向正式的、具有风险意识的授权

基本信息

  • 批准号:
    0963715
  • 负责人:
  • 金额:
    $ 35.05万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Continuing Grant
  • 财政年份:
    2010
  • 资助国家:
    美国
  • 起止时间:
    2010-06-01 至 2015-05-31
  • 项目状态:
    已结题

项目摘要

Traditional security authorization decisions are black and white: a user either satisfies a particular access policy or does not. This rigidity is a handicap in our complex and unpredictable world. As a result, even security-conscious organizations typically grossly overprovision principals with access rights and/or underconstrain access policies to ensure that principals can always carry out the organization's mission effectively and respond to unexpected opportunities and challenges. This project focuses on developing dynamic and risk-aware approaches to access control that allow organizations to make security-critical decisions in the face of incomplete information and unexpected circumstances. This is accomplished by combining proof-theoretic access controls with economic models of risk. In the event that the expected proof of authorization for an action cannot be generated, the systems developed in this project carry out an efficient search for similar proofs of authorization that minimize the overall risk incurred by deviating from the expected. This approach allows policies to adapt dynamically to the changing context of the systems in which they are deployed. This research will have several benefits, including increased system availability during disasters or other uncommon cases not explicitly modeled by policies; reduced instances of permission creep, as overprovisioning users is no longer required to ensure that an organization's business needs are met; a quantifiable means of assessing how policies are actually used and how they might be changed to better reflect the evolution of organizations; and the development of metrics for assessing access control risks.
传统的安全授权决策是非黑即白的:用户要么满足特定的访问策略,要么不满足。在我们这个复杂和不可预测的世界里,这种僵化是一个障碍。因此,即使是具有安全意识的组织通常也会向主体过度提供访问权限和/或限制访问策略,以确保主体始终能够有效地执行组织的任务并应对意外的机会和挑战。该项目专注于开发动态且具有风险意识的访问控制方法,使组织能够在信息不完整和意外情况下做出安全关键决策。这是通过将证据理论访问控制与风险经济模型相结合来实现的。如果无法生成预期的行动授权证据,本项目中开发的系统将有效地搜索类似的授权证据,从而最大限度地减少因偏离预期而产生的总体风险。这种方法允许策略动态适应部署它们的系统不断变化的环境。这项研究将有几个好处,包括在灾难或其他未由策略明确建模的罕见情况下提高系统可用性;减少权限蠕变的实例,因为不再需要过度配置用户来确保组织的业务需求得到满足;评估策略的实际使用方式以及如何更改策略以更好地反映组织的发展;以及制定用于评估访问控制风险的指标。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Ninghui Li其他文献

PURE: A Framework for Analyzing Proximity-based Contact Tracing Protocols
PURE:用于分析基于接近度的接触追踪协议的框架
  • DOI:
  • 发表时间:
    2020
  • 期刊:
  • 影响因子:
    16.6
  • 作者:
    F. Cicala;Weicheng Wang;Tianhao Wang;Ninghui Li;E. Bertino;F. Liang;Yang Yang
  • 通讯作者:
    Yang Yang
A formal semantics for P3P
P3P 的形式化语义
  • DOI:
  • 发表时间:
    2004
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Ting Yu;Ninghui Li;A. Antón
  • 通讯作者:
    A. Antón
Fisher Information as a Utility Metric for Frequency Estimation under Local Differential Privacy
Fisher信息作为本地差分隐私下频率估计的效用度量
  • DOI:
  • 发表时间:
    2022
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Milan Lopuhaä;B. Škorić;Ninghui Li
  • 通讯作者:
    Ninghui Li
Sensornet
传感器网
  • DOI:
  • 发表时间:
    2009
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Rodney Topor;Kenneth Salem;Amarnath Gupta;K. Goda;John F. Gehrke;N. Palmer;Mohamed Sharaf;Alexandros Labrinidis;J. Roddick;Ariel Fuxman;Renée J. Miller;Wang;Anastasios Kementsietsidis;Philippe Bonnet;D. Shasha;Ronald Peikert;Bertram Ludäscher;S. Bowers;T. McPhillips;Harald Naumann;K. Voruganti;J. Domingo;Ben Carterette;Panagiotis G. Ipeirotis;Marcelo Arenas;Y. Manolopoulos;Y. Theodoridis;V. Tsotras;B. Carminati;Jan Jurjens;Eduardo B. Fernandez;Murat Kantarcıoǧlu;Jaideep Vaidya;Indrakshi Ray;Athena Vakali;Cristina Sirangelo;E. Pitoura;Himanshu Gupta;Surajit Chaudhuri;G. Weikum;Ulf Leser;David W. Embley;Fausto Giunchiglia;P. Shvaiko;Mikalai Yatskevich;Edward Y. Chang;Christine Parent;S. Spaccapietra;E. Zimányi;G. Anadiotis;S. Kotoulas;Ronny Siebes;Grigoris Antoniou;D. Plexousakis;J. Bailey;François Bry;Tim Furche;Sebastian Schaffert;David Martin;Gregory D. Speegle;Krithi Ramamritham;P. Chrysanthis;Kai;Stéphane Bressan;S. Abiteboul;D. Suciu;G. Dobbie;Tok Wang Ling;Sugato Basu;Ramesh Govindan;Michael H. Böhlen;C. S. Jensen;Jianyong Wang;K. Vidyasankar;A. Chan;Serge Mankovski;S. Elnikety;P. Valduriez;Yannis Velegrakis;Mario A. Nascimento;Michael Huggett;Andrew U. Frank;Yanchun Zhang;Guandong Xu;R. Snodgrass;Alan Fekete;Marcus Herzog;Konstantinos Morfonios;Y. Ioannidis;E. Wohlstadter;M. Matera;F. Schwagereit;Steffen Staab;Keir Fraser;Jingren Zhou;M. Mokbel;Walid G. Aref;Mirella M. Moro;Markus Schneider;Panos Kalnis;Gabriel Ghinita;Michael F. Goodchild;Shashi Shekhar;James Kang;Vijayaprasath Gandhi;Nikos Mamoulis;Betsy George;Michel Scholl;Agnès Voisard;Ralf Hartmut Güting;Yufei Tao;Dimitris Papadias;Peter Revesz;G. Kollios;E. Frentzos;Apostolos N. Papadopoulos;Bernhard Thalheim;Jovan Pehcevski;Benjamin Piwowarski;S. Theodoridis;Konstantinos Koutroumbas;George Karabatis;Don Chamberlin;Philip A. Bernstein;Michael H. Böhlen;J. Gamper;Ping Li;Kazimierz Subieta;S. Harizopoulos;Ethan Zhang;Yi Zhang;Theodore Johnson;Hans;S. Fienberg;Jiashun Jin;Radu Sion;C. Paice;Nikos Hardavellas;Ippokratis Pandis;Edie M. Rasmussen;Hiroshi Yoshida;G. Graefe;Bernd Reiner;Karl Hahn;K. Wada;T. Risch;Jiawei Han;Bolin Ding;Lukasz Golab;Michael Stonebraker;Bibudh Lahiri;Srikanta Tirthapura;Erik Vee;Yanif Ahmad;U. Çetintemel;Mitch Cherniack;S. Zdonik;Mariano P. Consens;M. Lalmas;R. Baeza;D. Hiemstra;Peer Krögerand;Arthur Zimek;Nick Craswell;Carson Kai;Maxime Crochemore;Thierry Lecroq;Arie Shoshani;Jimmy Lin;Hwanjo Yu;David B. Lomet;H. Hinterberger;Ninghui Li;Phillip B. Gibbons;Mouna Kacimi;Thomas Neumann
  • 通讯作者:
    Thomas Neumann
Anonymizing Network Traces with Temporal Pseudonym Consistency
通过时间假名一致性对网络跟踪进行匿名化

Ninghui Li的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Ninghui Li', 18)}}的其他基金

Collaborative Research: SaTC: CORE: Small: Differentially Private Data Synthesis: Practical Algorithms and Statistical Foundations
协作研究:SaTC:核心:小型:差分隐私数据合成:实用算法和统计基础
  • 批准号:
    2247794
  • 财政年份:
    2023
  • 资助金额:
    $ 35.05万
  • 项目类别:
    Continuing Grant
Collaborative Proposal: SaTC: Frontiers: Center for Distributed Confidential Computing (CDCC)
协作提案:SaTC:前沿:分布式机密计算中心 (CDCC)
  • 批准号:
    2207204
  • 财政年份:
    2022
  • 资助金额:
    $ 35.05万
  • 项目类别:
    Continuing Grant
SaTC: CORE: Medium: Collaborative: User-Centered Deployment of Differential Privacy
SaTC:核心:媒介:协作:以用户为中心的差异隐私部署
  • 批准号:
    1931443
  • 财政年份:
    2020
  • 资助金额:
    $ 35.05万
  • 项目类别:
    Standard Grant
RAPID: Collaborative: PPSRC: Privacy-Preserving Self-Reporting for COVID-19
RAPID:协作:PPSRC:COVID-19 隐私保护自我报告
  • 批准号:
    2034235
  • 财政年份:
    2020
  • 资助金额:
    $ 35.05万
  • 项目类别:
    Standard Grant
SaTC: CORE: Improving Password Ecosystem: A Holistic Approach
SaTC:核心:改进密码生态系统:整体方法
  • 批准号:
    1704587
  • 财政年份:
    2017
  • 资助金额:
    $ 35.05万
  • 项目类别:
    Standard Grant
EAGER: Bridging The Gap between Theory and Practice in Data Privacy
EAGER:弥合数据隐私理论与实践之间的差距
  • 批准号:
    1640374
  • 财政年份:
    2016
  • 资助金额:
    $ 35.05万
  • 项目类别:
    Standard Grant
TWC SBE: Medium: Collaborative: User-Centric Risk Communication and Control on Mobile Devices
TWC SBE:媒介:协作:移动设备上以用户为中心的风险沟通和控制
  • 批准号:
    1314688
  • 财政年份:
    2013
  • 资助金额:
    $ 35.05万
  • 项目类别:
    Standard Grant
TC: Small: Provably Private Microdata Publishing
TC:小型:可证明的私人微数据出版
  • 批准号:
    1116991
  • 财政年份:
    2011
  • 资助金额:
    $ 35.05万
  • 项目类别:
    Standard Grant
CCS Workshops Organization Supplement
CCS 研讨会组织补充
  • 批准号:
    1054001
  • 财政年份:
    2010
  • 资助金额:
    $ 35.05万
  • 项目类别:
    Standard Grant
TC:Medium:Collaborative Research:Techniques to Retrofit Legacy Code
TC:中:协作研究:改造遗留代码的技术
  • 批准号:
    0905442
  • 财政年份:
    2009
  • 资助金额:
    $ 35.05万
  • 项目类别:
    Standard Grant

相似海外基金

TC: Medium: Collaborative Research: Program Analysis for Smartphone Application Security
TC:媒介:协作研究:智能手机应用程序安全的程序分析
  • 批准号:
    1630037
  • 财政年份:
    2015
  • 资助金额:
    $ 35.05万
  • 项目类别:
    Standard Grant
TC: Medium: Collaborative Research: Program Analysis for Smartphone Application Security
TC:媒介:协作研究:智能手机应用程序安全的程序分析
  • 批准号:
    1064646
  • 财政年份:
    2011
  • 资助金额:
    $ 35.05万
  • 项目类别:
    Standard Grant
TC: Medium: Collaborative Research: Building Trustworthy Applications for Mobile Devices
TC:媒介:协作研究:为移动设备构建值得信赖的应用程序
  • 批准号:
    1064944
  • 财政年份:
    2011
  • 资助金额:
    $ 35.05万
  • 项目类别:
    Standard Grant
TC: Medium: Collaborative Research: Securing Web Advertisements: Fixing the Short-term Crisis and Addressing Long-term Challenges
TC:媒介:协作研究:保护网络广告:解决短期危机并应对长期挑战
  • 批准号:
    1065216
  • 财政年份:
    2011
  • 资助金额:
    $ 35.05万
  • 项目类别:
    Standard Grant
TC: Medium: Collaborative Research: Tracking Adversarial Behavior in Distributed Systems with Secure Networked Provenance
TC:中:协作研究:通过安全网络来源跟踪分布式系统中的对抗行为
  • 批准号:
    1065130
  • 财政年份:
    2011
  • 资助金额:
    $ 35.05万
  • 项目类别:
    Standard Grant
TC: Medium: Collaborative Research: Securing Web Advertisements: Fixing the Short-term Crisis and Addressing Long-term Challenges
TC:媒介:协作研究:保护网络广告:解决短期危机并应对长期挑战
  • 批准号:
    1065537
  • 财政年份:
    2011
  • 资助金额:
    $ 35.05万
  • 项目类别:
    Standard Grant
TC: Medium: Collaborative Research: Program Analysis for Smartphone Application Security
TC:媒介:协作研究:智能手机应用程序安全的程序分析
  • 批准号:
    1064844
  • 财政年份:
    2011
  • 资助金额:
    $ 35.05万
  • 项目类别:
    Standard Grant
TC: Medium: Collaborative Research: Tracking Adversarial Behavior in Distributed Systems with Secure Networked Provenance
TC:中:协作研究:通过安全网络来源跟踪分布式系统中的对抗行为
  • 批准号:
    1064986
  • 财政年份:
    2011
  • 资助金额:
    $ 35.05万
  • 项目类别:
    Standard Grant
TC: Medium: Collaborative Research: Building Trustworthy Applications for Mobile Devices
TC:媒介:协作研究:为移动设备构建值得信赖的应用程序
  • 批准号:
    1064900
  • 财政年份:
    2011
  • 资助金额:
    $ 35.05万
  • 项目类别:
    Standard Grant
TC: Medium: Collaborative Research: Random Number Generation and Use in Virtualized Environments
TC:媒介:协作研究:虚拟化环境中的随机数生成和使用
  • 批准号:
    1065288
  • 财政年份:
    2011
  • 资助金额:
    $ 35.05万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了