课题基金 / 基金详情

TWC: Medium: Collaborative: Foundations of Application-Sensitive Access Control Evaluation

TWC: Medium: Collaborative: Foundations of Application-Sensitive Access Control Evaluation
TWC:媒介:协作:应用程序敏感的访问控制评估的基础
批准号:
1228947
负责人:
Lenore Zuck
金额:
$65.33万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2012
资助国家:
美国
项目状态:
已结题
起止时间:
2012-09-01 至 2016-08-31

项目摘要

项目成果

Lenore Zuck的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Access control schemes are traditionally compared in terms of raw expressive power (i.e., the policies they can encode and how those policies can be changed); however, such comparisons ignore the needs of the application within which a scheme will be deployed. For some applications, the most expressive scheme may be overly complex and not necessarily the best fit. To this end, this project investigates the suitability analysis problem: Given a system's access control workload, a set of candidate access control schemes, and a set of application-specific cost metrics, which scheme best meets the needs of the system?The goal is to create a suitability-analysis framework that is sufficiently rigorous to be useful to researchers and theoreticians, while remaining accessible to security practitioners. Such a framework will help formalize an access control scheme's application-specific strengths and limitations, enable researchers to precisely describe the scenarios for which a scheme is best suited, allow assessment of the novelty and utility of proposed schemes, and help analysts diagnose shortcomings in existing systems. In particular, the project will develop (1) an application-specific, workload-based framework for analyzing the suitability of access control schemes that is sufficiently rich to compare logical, extensional, and hybrid schemes in both sequential and concurrent systems; (2) a cost analysis component that quantifies a scheme's suitability using custom metrics; and (3) tools that automate a range of suitability analysis tasks. A real-world security workload, PKI-based authentication and authorization on the web, will be used to evaluate the results.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
EAGER: A Roadmap for research towards verification of NextG technologies
  • 批准号:
    2140207
  • 项目类别:
    Standard Grant
  • 资助金额:
    $30.0万
  • 财政年份:
    2021
  • 负责人:
    Lenore Zuck
  • 依托单位:
FMitF: Track I: Injecting Formal Methods into Internet Standardization
  • 批准号:
    1918429
  • 项目类别:
    Standard Grant
  • 资助金额:
    $74.97万
  • 财政年份:
    2019
  • 负责人:
    Lenore Zuck
  • 依托单位:
SHF: Medium: Self-certifying Compilation and its Applications
  • 批准号:
    1564296
  • 项目类别:
    Standard Grant
  • 资助金额:
    $85.45万
  • 财政年份:
    2016
  • 负责人:
    Lenore Zuck
  • 依托单位:
Midwest Verification Day (MVD) 2013
  • 批准号:
    1341855
  • 项目类别:
    Standard Grant
  • 资助金额:
    $1.0万
  • 财政年份:
    2013
  • 负责人:
    Lenore Zuck
  • 依托单位:
海外基金