• DocumentCode
    2323269
  • Title

    Detection of Multiple-Duty-Related Security Leakage in Access Control Policies

  • Author

    Jeehyun Hwang ; Xie, Tao ; Hu, Vincent C.

  • Author_Institution
    Dept. of Comput. Sci., North Carolina State Univ., Raleigh, NC, USA
  • fYear
    2009
  • fDate
    8-10 July 2009
  • Firstpage
    65
  • Lastpage
    74
  • Abstract
    Access control mechanisms control which subjects (such as users or processes) have access to which resources. To facilitate managing access control, policy authors increasingly write access control policies in XACML. Access control policies written in XACML could be amenable to multiple-duty-related security leakage, which grants unauthorized access to a user when the user takes multiple duties (e.g., multiple roles in role-based access control policies). To help policy authors detect multiple-duty-related security leakage, we develop a novel framework that analyzes policies and detects cases that potentially cause the leakage. In such cases, a user taking multiple roles (e.g., both r1 and r2) is given a different access decision from the decision given to a user taking an individual role (e.g., r1 and r2, respectively). We conduct experiments on 11 XACML policies and our empirical results show that our framework effectively pinpoints potential multiple-duty-related security leakage for policy authors to inspect.
  • Keywords
    XML; authorisation; XACML; access control policies; multiple-duty-related security leakage detection; Access control; Computer science; Computer security; Control systems; Leak detection; Markup languages; NIST; National security; Permission; Specification languages; Access Control Policies; Policy Verification; Validation;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Secure Software Integration and Reliability Improvement, 2009. SSIRI 2009. Third IEEE International Conference on
  • Conference_Location
    Shanghai
  • Print_ISBN
    978-0-7695-3758-0
  • Type

    conf

  • DOI
    10.1109/SSIRI.2009.63
  • Filename
    5325389