DocumentCode
2517919
Title
Detecting policy misconfigurations in temporal domain using object priority
Author
Dammati, Madhu Sankeerth ; Mondal, Samrat
Author_Institution
Dept. of Comput. Sci. & Eng., Indian Inst. of Technol. Patna, Patna, India
fYear
2012
fDate
12-14 July 2012
Firstpage
147
Lastpage
151
Abstract
In an organization, one of the important job of an administrator is to define different access control policies based on the various requirements. Access-control policy misconfigurations that cause requests to be erroneously denied can result in wasted time, user frustration. Depending upon the context of particular applications (e.g., health care, national security) the effect may be quite severe. Identification of such possible inconsistencies in the access control system at an early stage even before the user tries to access them, can help in rectifying such mistakes. Access Control List (ACL) purely reflects the various policies that a system must follow to carry out the desirable tasks. For most of the access control systems the ACL remains the same. In recent times, such models are not sufficient enough to meet the requirements, leading to models like TRBAC, GTRBAC. Identification of policy misconfigurations in such systems helps in minimizing the vulnerabilities, reducing the security risks and insider attacks. And in certain scenarios the policies may not be simple and may involve priorities among objects, where there is a fair chance of having erroneous policies unknowingly. Thus, identification of misconfigurations in such cases is of prior importance.
Keywords
access control; ACL; GTRBAC; TRBAC; access control list; access control policies; access control system; access-control policy misconfigurations; health care; insider attacks; national security; object priority; policy misconfigurations detection; security risks; temporal domain; Access control; Medical services; National security; Organizations; Permission; Servers;
fLanguage
English
Publisher
ieee
Conference_Titel
Communication, Networks and Satellite (ComNetSat), 2012 IEEE International Conference on
Conference_Location
Bali
Print_ISBN
978-1-4673-0888-5
Type
conf
DOI
10.1109/ComNetSat.2012.6380795
Filename
6380795
Link To Document