Efficient Policy Analysis for Evolving Administrative Role Based Access Control
    Download PDF
Mikhail I. Gofman,Ping Yang. Efficient Policy Analysis for Evolving Administrative Role Based Access Control. International Journal of Software and Informatics, 2014,8(1):95~131
Hits: 2343
Download times: 2091
Fund:This work was supported in part by United States National Science Foundation Grant CNS-0855204.
Abstract:Role Based Access Control (RBAC) has been widely used for restricting resource access to only authorized users. Administrative Role Based Access Control (ARBAC) specifies permissions for administrators to change RBAC policies. Due to complex interactions between changes made by different administrators, it is often difficult to comprehend the full effect of ARBAC policies by manual inspection alone. Policy analysis helps administrators detect potential flaws in the policy specification. Prior work on ARBAC policy analysis considers only static ARBAC policies. In practice, ARBAC policies tend to change over time in order to fix design flaws or to cope with the changing requirements of an organization. Changes to ARBAC policies may invalidate security properties that were previously satisfied. In this paper, we present incremental analysis algorithms for evolving ARBAC. Our incremental algorithms determine if a change may affect the analysis result, and if so, use the information of the previous analysis to incrementally update the analysis result. To the best of our knowledge, these are the first known incremental algorithms in literature for ARBAC analysis. Detailed evaluations show that our incremental algorithms outperform the non-incremental algorithm in terms of execution time at a reasonable cost of increased disk space consumption.
keywords:security  administrative role-based access control  security policy analysis
View Full Text  View/Add Comment  Download reader

 

 

more>>  
Visitor:3140946
Top Paper  |  E-mail Alert  |  Publication Ethics  |  New Version

© Copyright by Institute of Software, the Chinese Academy of Sciences
京ICP备05046678号-5

京公网安备 11040202500065号