Title :
A study of least privilege in CapBasED-AMS
Author :
Hung, Patrick C K ; Karlapalem, Kamalakar ; Gray, James W., III
Author_Institution :
Dept. of Comput. Sci., Hong Kong Univ. of Sci. & Technol., Hong Kong
Abstract :
Workflow systems are becoming very popular and are being used to support many of the day to day activities in large organizations. One of the major problems with workflow systems is that they often use heterogeneous and distributed hardware and software systems to execute a given activity. This gives rise to decentralized security policies and mechanisms, which, in order to enable activity execution, give too many privileges to agents (humans or systems) for executing the work. We develop the concept of least privilege, wherein the set of agents are given just enough privileges to complete the given activities. We develop our concepts in the context of CapBasED-AMS (Capability-based and Event-driven Activity Management System). CapBasED-AMS deals with the management and execution of activities. An activity consists of multiple inter-dependent tasks (atomic activities, each executed by a single agent) that need to be coordinated, scheduled and executed by a set of agents. We formalize the concept of least privilege and present algorithms to statically assign least privilege assignment to the agents. We develop the concept of dynamic least privilege enforcement, wherein an agent is given its privileges only during the duration of the task for which those privileges were assigned. Finally, we introduce a metric, security risk factor and use it to evaluate the trade-off between least privilege and resilience to agent failure.
Keywords :
authorisation; distributed processing; office automation; supervisory programs; CapBasED-AMS; Capability-based and Event-driven Activity Management System; activity execution; agent failure; atomic activities; decentralized security policies; dynamic least privilege enforcement; heterogeneous distributed hardware; least privilege; multiple inter-dependent tasks; security risk factor; software metric; workflow systems; Application software; Computer science; Hardware; Humans; Information security; Laboratories; Postal services; Resource management; Risk management; Software systems;
Conference_Titel :
Cooperative Information Systems, 1998. Proceedings. 3rd IFCIS International Conference on
Conference_Location :
New York, NY, USA
Print_ISBN :
0-8186-8380-5
DOI :
10.1109/COOPIS.1998.706199