Towards Efficient Evaluation of XACML Policies

被引:0
|
作者
Mourad, Azzam [1 ]
Jebbaoui, Hussein [1 ]
机构
[1] Lebanese Amer Univ, Dept Comp Sci & Math, Beirut, Lebanon
关键词
Web Services Security; Set-Based Algebra; Policy Evaluation; Real-Time Decision; Access Control; XACML;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Policy-based computing is taking an increasing role in providing real-time decisions and governing the systematic interaction among distributed cloud and Web services. XACML has been known as the de facto standard widely used by many vendors for specifying access control and context-aware policies. Accordingly, the size and complexity of XACML policies are significantly growing to cope with the evolution of web-based applications. This growth raised many concerns related to the efficiency of real-time decision process (i.e. policy evaluation). This paper is addressing this concern through the elaboration of SBA-XACML, a novel set-based algebra scheme that provides efficient evaluation of XACML policies. Our approach constitutes of elaborating (1) set-based language that covers all the XACML components and establish an intermediate layer to which policies are automatically converted, and (2) policy evaluation module that provides better performance compared to the industrial standard Sun Policy Decision Point (PDP) and its corresponding ameliorations. Experiments have been conducted on real-life and synthetic XACML policies in order to demonstrate the efficiency, relevance and scalability of our proposition. The experimental results explore that SBA-XACML evaluation of large and small sizes policies offers better performance than the current approaches, by a factor ranging between 2.4 and 15 times faster depending on policy size.
引用
收藏
页码:164 / 171
页数:8
相关论文
共 50 条
  • [1] Towards a Theory on Testing XACML Policies
    Xu, Dianxiang
    Shrestha, Roshan
    Shen, Ning
    Zhang, Yunpeng
    PROCEEDINGS OF THE 27TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, SACMAT 2022, 2022, : 103 - 114
  • [2] Approaches for Testing and Evaluation of XACML Policies
    Alsmadi, Izzat M.
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2014, 8 (04): : 101 - 111
  • [3] Analysis of XACML policies with SMT
    Turkmen, Fatih
    Den Hartog, Jerry
    Ranise, Silvio
    Zannone, Nicola
    Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 2015, 9036 : 115 - 134
  • [4] Challenges of Composing XACML Policies
    Stepien, Bernard
    Felty, Amy
    Matwin, Stan
    2014 NINTH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES), 2015, : 234 - 241
  • [5] Establishment of attribute bitmaps for efficient XACML policy evaluation
    Deng, Fan
    Wang, Shiyu
    Zhang, Liyong
    Wei, Xiaoqian
    Yu, Jingping
    KNOWLEDGE-BASED SYSTEMS, 2018, 143 : 93 - 101
  • [6] Analysis of XACML Policies with ASP
    Ayed, Dhouha
    Lepareux, Marie-Noelle
    Martins, Cyrille
    2015 7TH INTERNATIONAL CONFERENCE ON NEW TECHNOLOGIES, MOBILITY AND SECURITY (NTMS), 2015,
  • [7] An efficient policy evaluation engine for XACML policy management
    Deng, Fan
    Yu, Zhenhua
    Liu, Wenjing
    Luo, Xiaoqing
    Fu, Yu
    Qiang, Ben
    Xu, Chaoyang
    Li, Zhiwu
    INFORMATION SCIENCES, 2021, 547 : 1105 - 1121
  • [8] Integrity-Preserving and Efficient Policy Evaluation for XACML
    Zheng, Kai
    Tian, Xiuxia
    International Journal of Network Security, 2022, 24 (02): : 262 - 272
  • [9] Evaluating Distributed XACML Policies
    Dhankhar, Vijayant
    Kaushik, Saket
    Wijesekera, Duminda
    Nerode, Anil
    SWS'07: PROCEEDINGS OF THE 2007 ACM WORKSHOP ON SECURE WEB SERVICES, 2007, : 99 - 110
  • [10] An ACO-based Algorithm for Efficient XACML Policy Evaluation
    Zhang, Yunpeng
    Zhang, Beibei
    PROCEEDINGS OF THE 2017 2ND INTERNATIONAL CONFERENCE ON CONTROL, AUTOMATION AND ARTIFICIAL INTELLIGENCE (CAAI 2017), 2017, 134 : 282 - 288