DocumentCode :
2323269
Title :
Detection of Multiple-Duty-Related Security Leakage in Access Control Policies
Author :
Jeehyun Hwang ; Xie, Tao ; Hu, Vincent C.
Author_Institution :
Dept. of Comput. Sci., North Carolina State Univ., Raleigh, NC, USA
fYear :
2009
fDate :
8-10 July 2009
Firstpage :
65
Lastpage :
74
Abstract :
Access control mechanisms control which subjects (such as users or processes) have access to which resources. To facilitate managing access control, policy authors increasingly write access control policies in XACML. Access control policies written in XACML could be amenable to multiple-duty-related security leakage, which grants unauthorized access to a user when the user takes multiple duties (e.g., multiple roles in role-based access control policies). To help policy authors detect multiple-duty-related security leakage, we develop a novel framework that analyzes policies and detects cases that potentially cause the leakage. In such cases, a user taking multiple roles (e.g., both r1 and r2) is given a different access decision from the decision given to a user taking an individual role (e.g., r1 and r2, respectively). We conduct experiments on 11 XACML policies and our empirical results show that our framework effectively pinpoints potential multiple-duty-related security leakage for policy authors to inspect.
Keywords :
XML; authorisation; XACML; access control policies; multiple-duty-related security leakage detection; Access control; Computer science; Computer security; Control systems; Leak detection; Markup languages; NIST; National security; Permission; Specification languages; Access Control Policies; Policy Verification; Validation;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Secure Software Integration and Reliability Improvement, 2009. SSIRI 2009. Third IEEE International Conference on
Conference_Location :
Shanghai
Print_ISBN :
978-0-7695-3758-0
Type :
conf
DOI :
10.1109/SSIRI.2009.63
Filename :
5325389
Link To Document :
بازگشت