DocumentCode
2323269
Title
Detection of Multiple-Duty-Related Security Leakage in Access Control Policies
Author
Jeehyun Hwang ; Xie, Tao ; Hu, Vincent C.
Author_Institution
Dept. of Comput. Sci., North Carolina State Univ., Raleigh, NC, USA
fYear
2009
fDate
8-10 July 2009
Firstpage
65
Lastpage
74
Abstract
Access control mechanisms control which subjects (such as users or processes) have access to which resources. To facilitate managing access control, policy authors increasingly write access control policies in XACML. Access control policies written in XACML could be amenable to multiple-duty-related security leakage, which grants unauthorized access to a user when the user takes multiple duties (e.g., multiple roles in role-based access control policies). To help policy authors detect multiple-duty-related security leakage, we develop a novel framework that analyzes policies and detects cases that potentially cause the leakage. In such cases, a user taking multiple roles (e.g., both r1 and r2) is given a different access decision from the decision given to a user taking an individual role (e.g., r1 and r2, respectively). We conduct experiments on 11 XACML policies and our empirical results show that our framework effectively pinpoints potential multiple-duty-related security leakage for policy authors to inspect.
Keywords
XML; authorisation; XACML; access control policies; multiple-duty-related security leakage detection; Access control; Computer science; Computer security; Control systems; Leak detection; Markup languages; NIST; National security; Permission; Specification languages; Access Control Policies; Policy Verification; Validation;
fLanguage
English
Publisher
ieee
Conference_Titel
Secure Software Integration and Reliability Improvement, 2009. SSIRI 2009. Third IEEE International Conference on
Conference_Location
Shanghai
Print_ISBN
978-0-7695-3758-0
Type
conf
DOI
10.1109/SSIRI.2009.63
Filename
5325389
Link To Document