课题基金 / 基金详情

TC: Medium: Collaborative Research: Towards Formal, Risk-Aware Authorization

TC: Medium: Collaborative Research: Towards Formal, Risk-Aware Authorization
TC:媒介:协作研究:迈向正式的、具有风险意识的授权
批准号:
0963943
负责人:
Marianne Winslett
金额:
$32.59万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2010
资助国家:
美国
项目状态:
已结题
起止时间:
2010-06-01 至 2015-05-31

项目摘要

项目成果

Marianne Winslett的其他基金

相似基金

相关文献

中文摘要
翻译
传统的安全授权决策是非黑即白的:用户要么满足特定的访问策略,要么不满足。在我们这个复杂而不可预测的世界里,这种僵化是一种障碍。因此,即使是具有安全意识的组织,通常也会过度为主体提供访问权限和/或限制访问策略不足,以确保主体始终能够有效地执行组织的任务并响应意外的机会和挑战。该项目侧重于开发访问控制的动态和风险意识方法,使组织能够在面对不完整的信息和意外情况时做出安全关键决策。这是通过将证明理论访问控制与风险的经济模型相结合来实现的。如果无法生成操作的预期授权证明,本项目开发的系统将有效地搜索类似的授权证明,从而最大限度地减少因偏离预期而产生的总体风险。这种方法允许策略动态地适应部署它们的系统的不断变化的上下文。这项研究将有几个好处,包括在灾难或其他不常见的情况下增加系统可用性;减少权限蔓延的实例,因为不再需要过度配置用户来确保满足组织的业务需求;一种可量化的方法来评估政策的实际使用情况以及如何改变政策以更好地反映组织的演变;开发用于评估访问控制风险的度量标准。
英文摘要
Traditional security authorization decisions are black and white: a user either satisfies a particular access policy or does not. This rigidity is a handicap in our complex and unpredictable world. As a result, even security-conscious organizations typically grossly overprovision principals with access rights and/or underconstrain access policies to ensure that principals can always carry out the organization's mission effectively and respond to unexpected opportunities and challenges. This project focuses on developing dynamic and risk-aware approaches to access control that allow organizations to make security-critical decisions in the face of incomplete information and unexpected circumstances. This is accomplished by combining proof-theoretic access controls with economic models of risk. In the event that the expected proof of authorization for an action cannot be generated, the systems developed in this project carry out an efficient search for similar proofs of authorization that minimize the overall risk incurred by deviating from the expected. This approach allows policies to adapt dynamically to the changing context of the systems in which they are deployed. This research will have several benefits, including increased system availability during disasters or other uncommon cases not explicitly modeled by policies; reduced instances of permission creep, as overprovisioning users is no longer required to ensure that an organization's business needs are met; a quantifiable means of assessing how policies are actually used and how they might be changed to better reflect the evolution of organizations; and the development of metrics for assessing access control risks.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
EAGER: Identifying and Capitalizing on Schools of Thought as a Basis for Virtual Communities in Computer Science and Engineering Research
NSF Student Travel Grant for 2017 ACM Conference on Information and Knowledge Management (CIKM)
Collaborative Research: Personalized Benchmarks for High Performance Computing Applications
III: Small: Collaborative Research: Generalizable Similarity and Proximity Metrics for Data Exploration
海外基金