• DocumentCode
    2517919
  • Title

    Detecting policy misconfigurations in temporal domain using object priority

  • Author

    Dammati, Madhu Sankeerth ; Mondal, Samrat

  • Author_Institution
    Dept. of Comput. Sci. & Eng., Indian Inst. of Technol. Patna, Patna, India
  • fYear
    2012
  • fDate
    12-14 July 2012
  • Firstpage
    147
  • Lastpage
    151
  • Abstract
    In an organization, one of the important job of an administrator is to define different access control policies based on the various requirements. Access-control policy misconfigurations that cause requests to be erroneously denied can result in wasted time, user frustration. Depending upon the context of particular applications (e.g., health care, national security) the effect may be quite severe. Identification of such possible inconsistencies in the access control system at an early stage even before the user tries to access them, can help in rectifying such mistakes. Access Control List (ACL) purely reflects the various policies that a system must follow to carry out the desirable tasks. For most of the access control systems the ACL remains the same. In recent times, such models are not sufficient enough to meet the requirements, leading to models like TRBAC, GTRBAC. Identification of policy misconfigurations in such systems helps in minimizing the vulnerabilities, reducing the security risks and insider attacks. And in certain scenarios the policies may not be simple and may involve priorities among objects, where there is a fair chance of having erroneous policies unknowingly. Thus, identification of misconfigurations in such cases is of prior importance.
  • Keywords
    access control; ACL; GTRBAC; TRBAC; access control list; access control policies; access control system; access-control policy misconfigurations; health care; insider attacks; national security; object priority; policy misconfigurations detection; security risks; temporal domain; Access control; Medical services; National security; Organizations; Permission; Servers;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communication, Networks and Satellite (ComNetSat), 2012 IEEE International Conference on
  • Conference_Location
    Bali
  • Print_ISBN
    978-1-4673-0888-5
  • Type

    conf

  • DOI
    10.1109/ComNetSat.2012.6380795
  • Filename
    6380795