TWC: Medium: Collaborative: Foundations of Application-Sensitive Access Control Evaluation
TWC:媒介:协作:应用程序敏感的访问控制评估的基础
基本信息
- 批准号:1228947
- 负责人:
- 金额:$ 65.33万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2012
- 资助国家:美国
- 起止时间:2012-09-01 至 2016-08-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Access control schemes are traditionally compared in terms of raw expressive power (i.e., the policies they can encode and how those policies can be changed); however, such comparisons ignore the needs of the application within which a scheme will be deployed. For some applications, the most expressive scheme may be overly complex and not necessarily the best fit. To this end, this project investigates the suitability analysis problem: Given a system's access control workload, a set of candidate access control schemes, and a set of application-specific cost metrics, which scheme best meets the needs of the system?The goal is to create a suitability-analysis framework that is sufficiently rigorous to be useful to researchers and theoreticians, while remaining accessible to security practitioners. Such a framework will help formalize an access control scheme's application-specific strengths and limitations, enable researchers to precisely describe the scenarios for which a scheme is best suited, allow assessment of the novelty and utility of proposed schemes, and help analysts diagnose shortcomings in existing systems. In particular, the project will develop (1) an application-specific, workload-based framework for analyzing the suitability of access control schemes that is sufficiently rich to compare logical, extensional, and hybrid schemes in both sequential and concurrent systems; (2) a cost analysis component that quantifies a scheme's suitability using custom metrics; and (3) tools that automate a range of suitability analysis tasks. A real-world security workload, PKI-based authentication and authorization on the web, will be used to evaluate the results.
访问控制方案传统上是根据原始表达能力(即,它们可以编码的策略以及这些策略可以如何改变);然而,这样的比较忽略了将在其中部署方案的应用的需要。 对于某些应用程序,最具表现力的方案可能过于复杂,不一定是最适合的。为此,该项目研究的适用性分析问题:给定系统的访问控制工作量,一组候选的访问控制方案,和一组特定于应用程序的成本指标,该方案最能满足系统的需求?我们的目标是创建一个足够严格的适用性分析框架,对研究人员和理论家有用,同时保持安全从业人员的可访问性。这样一个框架将有助于正式的访问控制方案的应用程序特定的优势和局限性,使研究人员能够精确地描述方案最适合的场景,允许评估的新奇和实用性的建议计划,并帮助分析师诊断现有系统的缺点。 特别是,该项目将开发(1)一个特定于应用程序的,基于工作量的框架,用于分析访问控制方案的适用性,该框架足够丰富,可以在顺序和并发系统中比较逻辑,扩展和混合方案;(2)一个成本分析组件,使用自定义指标量化方案的适用性;以及(3)自动执行一系列适用性分析任务的工具。 一个真实世界的安全工作量,基于公钥基础设施的身份验证和授权的网络上,将被用来评估结果。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Lenore Zuck其他文献
Liveness with invisible ranking
- DOI:
10.1007/s10009-005-0193-x - 发表时间:
2006-03-17 - 期刊:
- 影响因子:1.400
- 作者:
Yi Fang;Nir Piterman;Amir Pnueli;Lenore Zuck - 通讯作者:
Lenore Zuck
Lenore Zuck的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Lenore Zuck', 18)}}的其他基金
EAGER: A Roadmap for research towards verification of NextG technologies
EAGER:NextG 技术验证研究路线图
- 批准号:
2140207 - 财政年份:2021
- 资助金额:
$ 65.33万 - 项目类别:
Standard Grant
FMitF: Track I: Injecting Formal Methods into Internet Standardization
FMITF:第一轨:将形式化方法注入互联网标准化
- 批准号:
1918429 - 财政年份:2019
- 资助金额:
$ 65.33万 - 项目类别:
Standard Grant
SHF: Medium: Self-certifying Compilation and its Applications
SHF:Medium:自认证编译及其应用
- 批准号:
1564296 - 财政年份:2016
- 资助金额:
$ 65.33万 - 项目类别:
Standard Grant
Midwest Verification Day (MVD) 2013
2013 年中西部验证日 (MVD)
- 批准号:
1341855 - 财政年份:2013
- 资助金额:
$ 65.33万 - 项目类别:
Standard Grant
EAGER: From Devlopment Tools to Secure Web Applications
EAGER:从开发工具到安全 Web 应用程序
- 批准号:
1141863 - 财政年份:2011
- 资助金额:
$ 65.33万 - 项目类别:
Standard Grant
Translation Validation of Advanced Compiler Optimizations
高级编译器优化的翻译验证
- 批准号:
0456163 - 财政年份:2004
- 资助金额:
$ 65.33万 - 项目类别:
Continuing Grant
Translation Validation of Advanced Compiler Optimizations
高级编译器优化的翻译验证
- 批准号:
0306538 - 财政年份:2003
- 资助金额:
$ 65.33万 - 项目类别:
Continuing Grant
CCR: The First Annual Conference on Verification, Model Checking and Abstract Interpretation 2003
CCR:2003 年第一届验证、模型检查和摘要解释年会
- 批准号:
0223760 - 财政年份:2002
- 资助金额:
$ 65.33万 - 项目类别:
Standard Grant
Translation Validation of Advanced Compiler Optimizations
高级编译器优化的翻译验证
- 批准号:
0098299 - 财政年份:2001
- 资助金额:
$ 65.33万 - 项目类别:
Standard Grant
Applications of Knowledge Theory to Distributed Systems
知识论在分布式系统中的应用
- 批准号:
8910289 - 财政年份:1989
- 资助金额:
$ 65.33万 - 项目类别:
Standard Grant
相似海外基金
TWC SBE: Medium: Collaborative: Brain Hacking: Assessing Psychological and Computational Vulnerabilities in Brain-based Biometrics
TWC SBE:媒介:协作:大脑黑客:评估基于大脑的生物识别技术中的心理和计算漏洞
- 批准号:
1840790 - 财政年份:2018
- 资助金额:
$ 65.33万 - 项目类别:
Continuing Grant
TWC: Medium: Collaborative: Black-Box Evaluation of Cryptographic Entropy at Scale
TWC:媒介:协作:大规模密码熵的黑盒评估
- 批准号:
1937622 - 财政年份:2018
- 资助金额:
$ 65.33万 - 项目类别:
Standard Grant
TWC SBE: Medium: Collaborative: Building a Privacy-Preserving Social Networking Platform from a Technological and Sociological Perspective
TWC SBE:媒介:协作:从技术和社会学角度构建保护隐私的社交网络平台
- 批准号:
1855391 - 财政年份:2018
- 资助金额:
$ 65.33万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Systems, Tools, and Techniques for Executing, Managing, and Securing SGX Programs
TWC:媒介:协作:用于执行、管理和保护 SGX 程序的系统、工具和技术
- 批准号:
1834213 - 财政年份:2018
- 资助金额:
$ 65.33万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Efficient Repair of Learning Systems via Machine Unlearning
TWC:媒介:协作:通过机器取消学习有效修复学习系统
- 批准号:
1854000 - 财政年份:2018
- 资助金额:
$ 65.33万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Seal: Secure Engine for AnaLytics - From Secure Similarity Search to Secure Data Analytics
TWC:媒介:协作:Seal:AnaLytics 的安全引擎 - 从安全相似性搜索到安全数据分析
- 批准号:
1929901 - 财政年份:2018
- 资助金额:
$ 65.33万 - 项目类别:
Standard Grant
TWC: TTP Option: Medium: Collaborative: MALDIVES: Developing a Comprehensive Understanding of Malware Delivery Mechanisms
TWC:TTP 选项:中:协作:马尔代夫:全面了解恶意软件传播机制
- 批准号:
1748127 - 财政年份:2017
- 资助金额:
$ 65.33万 - 项目类别:
Standard Grant
TWC SBE: Medium: Collaborative: Dollars for Hertz: Making Trustworthy Spectrum Sharing Technically and Economically Viable
TWC SBE:媒介:协作:赫兹美元:使值得信赖的频谱共享在技术上和经济上可行
- 批准号:
1801986 - 财政年份:2017
- 资助金额:
$ 65.33万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: New Protocols and Systems for RAM-Based Secure Computation
TWC:媒介:协作:基于 RAM 的安全计算的新协议和系统
- 批准号:
1562888 - 财政年份:2016
- 资助金额:
$ 65.33万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Systems, Tools, and Techniques for Executing, Managing, and Securing SGX Programs
TWC:媒介:协作:用于执行、管理和保护 SGX 程序的系统、工具和技术
- 批准号:
1563848 - 财政年份:2016
- 资助金额:
$ 65.33万 - 项目类别:
Standard Grant