TC: Medium: Collaborative Research: Towards Formal, Risk-Aware Authorization

TC:媒介:协作研究:迈向正式的、具有风险意识的授权

基本信息

项目摘要

Traditional security authorization decisions are black and white: a user either satisfies a particular access policy or does not. This rigidity is a handicap in our complex and unpredictable world. As a result, even security-conscious organizations typically grossly overprovision principals with access rights and/or underconstrain access policies to ensure that principals can always carry out the organization's mission effectively and respond to unexpected opportunities and challenges. This project focuses on developing dynamic and risk-aware approaches to access control that allow organizations to make security-critical decisions in the face of incomplete information and unexpected circumstances. This is accomplished by combining proof-theoretic access controls with economic models of risk. In the event that the expected proof of authorization for an action cannot be generated, the systems developed in this project carry out an efficient search for similar proofs of authorization that minimize the overall risk incurred by deviating from the expected. This approach allows policies to adapt dynamically to the changing context of the systems in which they are deployed. This research will have several benefits, including increased system availability during disasters or other uncommon cases not explicitly modeled by policies; reduced instances of permission creep, as overprovisioning users is no longer required to ensure that an organization's business needs are met; a quantifiable means of assessing how policies are actually used and how they might be changed to better reflect the evolution of organizations; and the development of metrics for assessing access control risks.
传统的安全授权决策是非黑即白的:用户要么满足特定的访问策略,要么不满足。在我们这个复杂和不可预测的世界里,这种僵化是一个障碍。因此,即使是具有安全意识的组织通常也会向主体过度提供访问权限和/或限制访问策略,以确保主体始终能够有效地执行组织的任务并应对意外的机会和挑战。该项目专注于开发动态且具有风险意识的访问控制方法,使组织能够在信息不完整和意外情况下做出安全关键决策。这是通过将证据理论访问控制与风险经济模型相结合来实现的。如果无法生成预期的行动授权证据,本项目中开发的系统将有效地搜索类似的授权证据,从而最大限度地减少因偏离预期而产生的总体风险。这种方法允许策略动态适应部署它们的系统不断变化的环境。这项研究将有几个好处,包括在灾难或其他未由策略明确建模的罕见情况下提高系统可用性;减少权限蠕变的实例,因为不再需要过度配置用户来确保组织的业务需求得到满足;评估策略的实际使用方式以及如何更改策略以更好地反映组织的发展;以及制定用于评估访问控制风险的指标。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Marianne Winslett其他文献

A model-based belief revision system
  • DOI:
    10.1007/bf00881886
  • 发表时间:
    1994-06-01
  • 期刊:
  • 影响因子:
    0.800
  • 作者:
    Timothy S. C. Chou;Marianne Winslett
  • 通讯作者:
    Marianne Winslett
Multidimensional array I/O in Panda 1.0
  • DOI:
    10.1007/bf00130709
  • 发表时间:
    1996-01-01
  • 期刊:
  • 影响因子:
    2.700
  • 作者:
    Kent E. Seamons;Marianne Winslett
  • 通讯作者:
    Marianne Winslett
Introduction to the special issue on networked information discovery and retrieval
Circumscriptive semantics for updating knowledge bases
Efficient Similarity Join Based on Earth Mover’s Distance Using MapReduce
使用 MapReduce 基于地球移动器距离的高效相似性连接

Marianne Winslett的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Marianne Winslett', 18)}}的其他基金

EAGER: Identifying and Capitalizing on Schools of Thought as a Basis for Virtual Communities in Computer Science and Engineering Research
EAGER:识别和利用思想流派作为计算机科学和工程研究虚拟社区的基础
  • 批准号:
    2040714
  • 财政年份:
    2020
  • 资助金额:
    $ 32.59万
  • 项目类别:
    Standard Grant
NSF Student Travel Grant for 2017 ACM Conference on Information and Knowledge Management (CIKM)
2017 年 ACM 信息与知识管理会议 (CIKM) 的 NSF 学生旅费补助
  • 批准号:
    1741803
  • 财政年份:
    2017
  • 资助金额:
    $ 32.59万
  • 项目类别:
    Standard Grant
Collaborative Research: Personalized Benchmarks for High Performance Computing Applications
协作研究:高性能计算应用程序的个性化基准
  • 批准号:
    1535177
  • 财政年份:
    2015
  • 资助金额:
    $ 32.59万
  • 项目类别:
    Standard Grant
III: Small: Collaborative Research: Generalizable Similarity and Proximity Metrics for Data Exploration
III:小:协作研究:数据探索的通用相似性和邻近性度量
  • 批准号:
    1421247
  • 财政年份:
    2014
  • 资助金额:
    $ 32.59万
  • 项目类别:
    Standard Grant
Collaborative Research: Automatic Extraction of Parallel I/O Benchmarks from HEC Applications
协作研究:从 HEC 应用程序中自动提取并行 I/O 基准
  • 批准号:
    0938064
  • 财政年份:
    2009
  • 资助金额:
    $ 32.59万
  • 项目类别:
    Standard Grant
Collaborative Research: Secure Provenance in High-End Computing Systems
协作研究:高端计算系统的安全来源
  • 批准号:
    0938071
  • 财政年份:
    2009
  • 资助金额:
    $ 32.59万
  • 项目类别:
    Standard Grant
III-COR Medium: Collaborative Research: Achieving Compliant Databases
III-COR 媒介:协作研究:实现合规数据库
  • 批准号:
    0803280
  • 财政年份:
    2008
  • 资助金额:
    $ 32.59万
  • 项目类别:
    Continuing Grant
CT-ISG: COLLABORATIVE RESEARCH: SecureWORM: Strong Regulatory-Compliant Storage
CT-ISG:协作研究:SecureWORM:强大的合规存储
  • 批准号:
    0716532
  • 财政年份:
    2007
  • 资助金额:
    $ 32.59万
  • 项目类别:
    Continuing Grant
Presidential Young Investigator Awards
总统青年研究员奖
  • 批准号:
    8958582
  • 财政年份:
    1989
  • 资助金额:
    $ 32.59万
  • 项目类别:
    Continuing Grant
Research Initiation: Relational Databases in a Hierarchical Design Environment
研究启动:分层设计环境中的关系数据库
  • 批准号:
    8809569
  • 财政年份:
    1989
  • 资助金额:
    $ 32.59万
  • 项目类别:
    Standard Grant

相似海外基金

TC: Medium: Collaborative Research: Program Analysis for Smartphone Application Security
TC:媒介:协作研究:智能手机应用程序安全的程序分析
  • 批准号:
    1630037
  • 财政年份:
    2015
  • 资助金额:
    $ 32.59万
  • 项目类别:
    Standard Grant
TC: Medium: Collaborative Research: Program Analysis for Smartphone Application Security
TC:媒介:协作研究:智能手机应用程序安全的程序分析
  • 批准号:
    1064646
  • 财政年份:
    2011
  • 资助金额:
    $ 32.59万
  • 项目类别:
    Standard Grant
TC: Medium: Collaborative Research: Building Trustworthy Applications for Mobile Devices
TC:媒介:协作研究:为移动设备构建值得信赖的应用程序
  • 批准号:
    1064944
  • 财政年份:
    2011
  • 资助金额:
    $ 32.59万
  • 项目类别:
    Standard Grant
TC: Medium: Collaborative Research: Securing Web Advertisements: Fixing the Short-term Crisis and Addressing Long-term Challenges
TC:媒介:协作研究:保护网络广告:解决短期危机并应对长期挑战
  • 批准号:
    1065216
  • 财政年份:
    2011
  • 资助金额:
    $ 32.59万
  • 项目类别:
    Standard Grant
TC: Medium: Collaborative Research: Tracking Adversarial Behavior in Distributed Systems with Secure Networked Provenance
TC:中:协作研究:通过安全网络来源跟踪分布式系统中的对抗行为
  • 批准号:
    1065130
  • 财政年份:
    2011
  • 资助金额:
    $ 32.59万
  • 项目类别:
    Standard Grant
TC: Medium: Collaborative Research: Securing Web Advertisements: Fixing the Short-term Crisis and Addressing Long-term Challenges
TC:媒介:协作研究:保护网络广告:解决短期危机并应对长期挑战
  • 批准号:
    1065537
  • 财政年份:
    2011
  • 资助金额:
    $ 32.59万
  • 项目类别:
    Standard Grant
TC: Medium: Collaborative Research: Program Analysis for Smartphone Application Security
TC:媒介:协作研究:智能手机应用程序安全的程序分析
  • 批准号:
    1064844
  • 财政年份:
    2011
  • 资助金额:
    $ 32.59万
  • 项目类别:
    Standard Grant
TC: Medium: Collaborative Research: Tracking Adversarial Behavior in Distributed Systems with Secure Networked Provenance
TC:中:协作研究:通过安全网络来源跟踪分布式系统中的对抗行为
  • 批准号:
    1064986
  • 财政年份:
    2011
  • 资助金额:
    $ 32.59万
  • 项目类别:
    Standard Grant
TC: Medium: Collaborative Research: Building Trustworthy Applications for Mobile Devices
TC:媒介:协作研究:为移动设备构建值得信赖的应用程序
  • 批准号:
    1064900
  • 财政年份:
    2011
  • 资助金额:
    $ 32.59万
  • 项目类别:
    Standard Grant
TC: Medium: Collaborative Research: Random Number Generation and Use in Virtualized Environments
TC:媒介:协作研究:虚拟化环境中的随机数生成和使用
  • 批准号:
    1065288
  • 财政年份:
    2011
  • 资助金额:
    $ 32.59万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了