DocumentCode :
3781531
Title :
Evaluating the comprehensive complexity of authorization-based access control policies using quantitative metrics
Author :
Malek Belhaouane;Joaquin Garcia-Alfaro;Hervé Debar
Author_Institution :
Institut Mines-Telecom, Té
Volume :
4
fYear :
2015
fDate :
7/1/2015 12:00:00 AM
Firstpage :
53
Lastpage :
64
Abstract :
Access control models allow flexible authoring and management of security policies, using high-level statements. They enable the expression of structured and expressive policies. However, they have an impact on the policy characteristics. The complexity of such policies is one of the affected characteristics. We propose a series of quantitative metrics to assess comprehensive complexity of policies. By comprehensive, we mean the difficulty of understanding a policy by administrators. We formalize the concepts of authorization-based access control models, to propose general metrics regardless of the model. We also show the application of the proposed metrics through a content management system (CMS) policy example. We outline a proof-of-concept to evaluate the feasibility of our proposal, based on SELinux policies for a general-purpose CMS.
Keywords :
"Access control","Concrete","Complexity theory","Measurement","Biological system modeling","Content management"
Publisher :
ieee
Conference_Titel :
e-Business and Telecommunications (ICETE), 2015 12th International Joint Conference on
Type :
conf
Filename :
7518021
Link To Document :
بازگشت