TWC: Small: Benchmarking Testing Methods for Access Control Policies
TWC: Small: Benchmarking Testing Methods for Access Control Policies
批准号:
1954327
负责人:
Dianxiang Xu
金额:
$28.52万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-09-01 至 2022-08-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Access control policies specify which users may perform which actions on which resources within which environments. Defective policies may have serious impacts, allowing unintended access (e.g., bank account withdrawals by a stranger) or preventing critical legitimate access (e.g., a doctor cannot view her patient's x-ray). As computer systems become more complex, policy defects have become more common. However, existing testing methods for detecting faults in access control policies have not been very successful and there is no explanation for why they are unable to detect a majority of faults. This project is investigating the inherent strengths, limitations, and cost-effectiveness of existing testing methods for access control policies. The results of this project will provide essential guidelines for planning testing efforts and selecting appropriate testing methods.The project focuses on access control policies expressed in the XACML language. The project is formalizing fault detection conditions that test cases must satisfy in order to detect specific types of access control faults. These conditions consist of reachability constraints, necessity constraints, and propagation constraints of various faults in XACML policies. They are used to determine the fault detection ability of a given testing method by evaluating whether or not its test cases satisfy the fault detection conditions. Based on the collective fault detection conditions of fault groups, the project is developing a method for generating optimal test suites using an efficient constraint solver. The optimal test suites are used to quantitatively measure cost-effectiveness levels of other testing methods in terms of the ratio between the number of faults detected (i.e., effectiveness) and the size of test suite generated (i.e., cost). Thus, the project is a study of benchmarking testing methods for access control policies.
期刊论文(3)
专著(0)
科研奖励(0)
会议论文
DOI:
10.1145/3450569.3463563
发表时间:
2021-06
期刊:
Proceedings of the 26th ACM Symposium on Access Control Models and Technologies
影响因子:
--
作者:
[Erzhuo Chen;Vladislav Dubrovenski;Dianxiang Xu]
通讯作者:
Erzhuo Chen;Vladislav Dubrovenski;Dianxiang Xu
DOI:
10.1145/3381991.3395599
发表时间:
2020-05
期刊:
Proceedings of the 25th ACM Symposium on Access Control Models and Technologies
影响因子:
--
作者:
[Dianxiang Xu;Roshan Shrestha;Ning Shen]
通讯作者:
Dianxiang Xu;Roshan Shrestha;Ning Shen
DOI:
10.1145/3532105.3535031
发表时间:
2022-06
期刊:
Proceedings of the 27th ACM on Symposium on Access Control Models and Technologies
影响因子:
--
作者:
[Dianxiang Xu;Roshan Shrestha;Ning Shen;Yunpeng Zhang]
通讯作者:
Dianxiang Xu;Roshan Shrestha;Ning Shen;Yunpeng Zhang
Building AI-Powered Responsible Workforce by Integrating Large Language Models into Computer Science Curriculum
-
批准号:2336061
-
项目类别:Standard Grant
-
资助金额:$75.0万
-
财政年份:2024
-
负责人:Dianxiang Xu
-
依托单位:
Collaborative Research: Education DCL: EAGER: Harnessing the Power of Large Language Models in Digital Forensics Education at MSI and HBCU
-
批准号:2333951
-
项目类别:Standard Grant
-
资助金额:$12.0万
-
财政年份:2023
-
负责人:Dianxiang Xu
-
依托单位:
FMitF: Track II: SMT-Based Reachability Analyzer of NGAC Policies
-
批准号:2318891
-
项目类别:Standard Grant
-
资助金额:$10.0万
-
财政年份:2023
-
负责人:Dianxiang Xu
-
依托单位:
EAGER: SaTC-EDU: Exploring Visualized and Explainable Artificial Intelligence to Improve Students’ Learning Experience in Digital Forensics Education
-
批准号:2039288
-
项目类别:Standard Grant
-
资助金额:$9.0万
-
财政年份:2021
-
负责人:Dianxiang Xu
-
依托单位:
TWC: Small: Benchmarking Testing Methods for Access Control Policies
-
批准号:1618229
-
项目类别:Standard Grant
-
资助金额:$49.71万
-
财政年份:2016
-
负责人:Dianxiang Xu
-
依托单位:
EDU: Developing a Software Artifact Repository for Software Assurance Education
-
批准号:1522847
-
项目类别:Standard Grant
-
资助金额:$30.0万
-
财政年份:2015
-
负责人:Dianxiang Xu
-
依托单位:
REU Site: Software Security
-
批准号:1461133
-
项目类别:Standard Grant
-
资助金额:$32.4万
-
财政年份:2015
-
负责人:Dianxiang Xu
-
依托单位:
TTP: Small: Automated Conformance Testing of Access Control and Obligation Policies
-
批准号:1318529
-
项目类别:Standard Grant
-
资助金额:$49.98万
-
财政年份:2013
-
负责人:Dianxiang Xu
-
依托单位:
TTP: Small: Automated Conformance Testing of Access Control and Obligation Policies
-
批准号:1359590
-
项目类别:Standard Grant
-
资助金额:$49.98万
-
财政年份:2013
-
负责人:Dianxiang Xu
-
依托单位:
REU Site: Information Assurance and Security
-
批准号:1004843
-
项目类别:Standard Grant
-
资助金额:$32.84万
-
财政年份:2010
-
负责人:Dianxiang Xu
-
依托单位:
国内基金
海外基金
登录
查看更多内容
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:
-
依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:10.0万元
-
批准年份:2022
-
负责人:张祥忠
-
依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
-
批准号:32000033
-
项目类别:青年科学基金项目
-
资助金额:24.0万元
-
批准年份:2020
-
负责人:林平
-
依托单位:
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
-
批准号:31972324
-
项目类别:面上项目
-
资助金额:58.0万元
-
批准年份:2019
-
负责人:高学文
-
依托单位:
变异链球菌small RNAs连接LuxS密度感应与生物膜形成的机制研究
-
批准号:81900988
-
项目类别:青年科学基金项目
-
资助金额:21.0万元
-
批准年份:2019
-
负责人:毛梦莹
-
依托单位:
肠道细菌关键small RNAs在克罗恩病发生发展中的功能和作用机制
-
批准号:31870821
-
项目类别:面上项目
-
资助金额:56.0万元
-
批准年份:2018
-
负责人:陈江宁
-
依托单位:
基于small RNA 测序技术解析鸽分泌鸽乳的分子机制
-
批准号:31802058
-
项目类别:青年科学基金项目
-
资助金额:26.0万元
-
批准年份:2018
-
负责人:麻慧
-
依托单位:
Small RNA介导的DNA甲基化调控的水稻草矮病毒致病机制
-
批准号:31772128
-
项目类别:面上项目
-
资助金额:60.0万元
-
批准年份:2017
-
负责人:吴建国
-
依托单位:
基于small RNA-seq的针灸治疗桥本甲状腺炎的免疫调控机制研究
-
批准号:81704176
-
项目类别:青年科学基金项目
-
资助金额:20.0万元
-
批准年份:2017
-
负责人:赵继梦
-
依托单位:
水稻OsSGS3与OsHEN1调控small RNAs合成及其对抗病性的调节
-
批准号:91640114
-
项目类别:重大研究计划
-
资助金额:85.0万元
-
批准年份:2016
-
负责人:何祖华
-
依托单位: