Towards Efficient Evaluation of XACML Policies

被引:0
|
作者
Mourad, Azzam [1 ]
Jebbaoui, Hussein [1 ]
机构
[1] Lebanese Amer Univ, Dept Comp Sci & Math, Beirut, Lebanon
关键词
Web Services Security; Set-Based Algebra; Policy Evaluation; Real-Time Decision; Access Control; XACML;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Policy-based computing is taking an increasing role in providing real-time decisions and governing the systematic interaction among distributed cloud and Web services. XACML has been known as the de facto standard widely used by many vendors for specifying access control and context-aware policies. Accordingly, the size and complexity of XACML policies are significantly growing to cope with the evolution of web-based applications. This growth raised many concerns related to the efficiency of real-time decision process (i.e. policy evaluation). This paper is addressing this concern through the elaboration of SBA-XACML, a novel set-based algebra scheme that provides efficient evaluation of XACML policies. Our approach constitutes of elaborating (1) set-based language that covers all the XACML components and establish an intermediate layer to which policies are automatically converted, and (2) policy evaluation module that provides better performance compared to the industrial standard Sun Policy Decision Point (PDP) and its corresponding ameliorations. Experiments have been conducted on real-life and synthetic XACML policies in order to demonstrate the efficiency, relevance and scalability of our proposition. The experimental results explore that SBA-XACML evaluation of large and small sizes policies offers better performance than the current approaches, by a factor ranging between 2.4 and 15 times faster depending on policy size.
引用
收藏
页码:164 / 171
页数:8
相关论文
共 50 条
  • [21] Implementing ACL-based Policies in XACML
    Karjoth, Guenter
    Schade, Andreas
    Van Herreweghen, Els
    24TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, PROCEEDINGS, 2008, : 183 - 192
  • [22] Adaptive Reordering and Clustering-Based Framework for Efficient XACML Policy Evaluation
    Marouf, Said
    Shehab, Mohamed
    Squicciarini, Anna
    Sundareswaran, Smitha
    IEEE TRANSACTIONS ON SERVICES COMPUTING, 2011, 4 (04) : 300 - 313
  • [23] Automated Coverage-Based Testing of XACML Policies
    Xu, Dianxiang
    Shrestha, Roshan
    Shen, Ning
    SACMAT'18: PROCEEDINGS OF THE 23RD ACM SYMPOSIUM ON ACCESS CONTROL MODELS & TECHNOLOGIES, 2018, : 3 - 14
  • [24] Use of XACML Policies for a Network Access Control Service
    Lopez, Gabriel
    Canovas, Oscar
    Gomez-Skarmeta, Antonio F.
    APPLIED PUBLIC KEY INFRASTRUCTURE, 2005, 128 : 111 - 122
  • [25] An Algebra for Fine-Grained Integration of XACML Policies
    Rao, Prathima
    Lin, Dan
    Bertino, Elisa
    Li, Ninghui
    Lobo, Jorge
    SACMAT'09: PROCEEDINGS OF THE 14TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, 2009, : 63 - 72
  • [26] Using microsoft office infopath to generate XACML policies
    Sanchez, Manuel
    Lopez, Gabriel
    Gomez-Skarmeta, Antonio E.
    Canovas, Oscar
    SECRYPT 2006: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY, 2006, : 379 - +
  • [27] XACML-Based composition policies for ambient networks
    Kamienski, Carlos
    Fidalgo, Joseane
    Dantas, Ramide
    Sadok, Djamel
    Ohlman, Boerje
    EIGHTH IEEE INTERNATIONAL WORKSHOP ON POLICIES FOR DISTRIBUTED SYSTEMS AND NETWORKS - PROCEEDINGS, 2007, : 77 - +
  • [28] Analyzing XACML policies using answer set programming
    Mohsen Rezvani
    David Rajaratnam
    Aleksandar Ignjatovic
    Maurice Pagnucco
    Sanjay Jha
    International Journal of Information Security, 2019, 18 : 465 - 479
  • [29] Towards Efficient Evaluation of ABAC Policies using High-Dimensional Indexing Techniques
    Paul, Proteet
    Sural, Shamik
    2021 THIRD IEEE INTERNATIONAL CONFERENCE ON TRUST, PRIVACY AND SECURITY IN INTELLIGENT SYSTEMS AND APPLICATIONS (TPS-ISA 2021), 2021, : 243 - 251
  • [30] Conformance checking of access control policies specified in XACML
    Hu, Vincent C.
    Martin, Evan
    Hwang, JeeHyun
    Xie, Tao
    COMPSAC 2007: THE THIRTY-FIRST ANNUAL INTERNATIONAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE, VOL II, PROCEEDINGS, 2007, : 275 - +