• DocumentCode
    185631
  • Title

    Access Control Policy Evolution: An Empirical Study

  • Author

    Jeehyun Hwang ; Da Young Lee ; Williams, Laurie ; Vouk, Mladen

  • Author_Institution
    SAS Inst. Inc., Cary, NC, USA
  • fYear
    2014
  • fDate
    3-6 Nov. 2014
  • Firstpage
    245
  • Lastpage
    254
  • Abstract
    Access control policies (ACPs) are necessary mechanisms for protection of critical resources and applications. As operational and security requirements of a system evolve, so do access control policies. It is important to help policy authors in effectively managing access control policies by providing insights into historical trends and evolution patterns of access control policies. We analyzed ACP evolution in three systems: Security Enhanced Linux (SELinux) operating system, Virtual Computing Laboratory (VCL) cloud, and a network intrusion detection (Snort) application. We propose an approach, which extracts evolution patterns based on the analysis of ACP historical change data. An evolution pattern indicates an abstraction of change in the permissions/privileges assigned to a group or a user. We then developed a model of ACPs evolution. We found eight frequently occurring evolution patterns across the three systems. In our context this model can predict evolution patterns in ACPs with a precision of 50-80%, a recall of 70-90% and an F-measure of 65-75%.
  • Keywords
    Linux; authorisation; cloud computing; data analysis; ACP evolution; ACP historical change data analysis; SELinux operating system; Security Enhanced Linux operating system; Snort; VCL cloud; Virtual Computing Laboratory cloud; access control policy evolution; network intrusion detection; Access control; Linux; Maintenance engineering; Market research; Predictive models; Software; access control policy; evolution; maintainability;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Software Reliability Engineering (ISSRE), 2014 IEEE 25th International Symposium on
  • Conference_Location
    Naples
  • ISSN
    1071-9458
  • Print_ISBN
    978-1-4799-6032-3
  • Type

    conf

  • DOI
    10.1109/ISSRE.2014.36
  • Filename
    6982631