DocumentCode
2044668
Title
A study of least privilege in CapBasED-AMS
Author
Hung, Patrick C K ; Karlapalem, Kamalakar ; Gray, James W., III
Author_Institution
Dept. of Comput. Sci., Hong Kong Univ. of Sci. & Technol., Hong Kong
fYear
1998
fDate
22-22 Aug. 1998
Firstpage
208
Lastpage
217
Abstract
Workflow systems are becoming very popular and are being used to support many of the day to day activities in large organizations. One of the major problems with workflow systems is that they often use heterogeneous and distributed hardware and software systems to execute a given activity. This gives rise to decentralized security policies and mechanisms, which, in order to enable activity execution, give too many privileges to agents (humans or systems) for executing the work. We develop the concept of least privilege, wherein the set of agents are given just enough privileges to complete the given activities. We develop our concepts in the context of CapBasED-AMS (Capability-based and Event-driven Activity Management System). CapBasED-AMS deals with the management and execution of activities. An activity consists of multiple inter-dependent tasks (atomic activities, each executed by a single agent) that need to be coordinated, scheduled and executed by a set of agents. We formalize the concept of least privilege and present algorithms to statically assign least privilege assignment to the agents. We develop the concept of dynamic least privilege enforcement, wherein an agent is given its privileges only during the duration of the task for which those privileges were assigned. Finally, we introduce a metric, security risk factor and use it to evaluate the trade-off between least privilege and resilience to agent failure.
Keywords
authorisation; distributed processing; office automation; supervisory programs; CapBasED-AMS; Capability-based and Event-driven Activity Management System; activity execution; agent failure; atomic activities; decentralized security policies; dynamic least privilege enforcement; heterogeneous distributed hardware; least privilege; multiple inter-dependent tasks; security risk factor; software metric; workflow systems; Application software; Computer science; Hardware; Humans; Information security; Laboratories; Postal services; Resource management; Risk management; Software systems;
fLanguage
English
Publisher
ieee
Conference_Titel
Cooperative Information Systems, 1998. Proceedings. 3rd IFCIS International Conference on
Conference_Location
New York, NY, USA
Print_ISBN
0-8186-8380-5
Type
conf
DOI
10.1109/COOPIS.1998.706199
Filename
706199
Link To Document