Towards Efficient Evaluation of XACML Policies

被引:0
|
作者
Mourad, Azzam [1 ]
Jebbaoui, Hussein [1 ]
机构
[1] Lebanese Amer Univ, Dept Comp Sci & Math, Beirut, Lebanon
关键词
Web Services Security; Set-Based Algebra; Policy Evaluation; Real-Time Decision; Access Control; XACML;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Policy-based computing is taking an increasing role in providing real-time decisions and governing the systematic interaction among distributed cloud and Web services. XACML has been known as the de facto standard widely used by many vendors for specifying access control and context-aware policies. Accordingly, the size and complexity of XACML policies are significantly growing to cope with the evolution of web-based applications. This growth raised many concerns related to the efficiency of real-time decision process (i.e. policy evaluation). This paper is addressing this concern through the elaboration of SBA-XACML, a novel set-based algebra scheme that provides efficient evaluation of XACML policies. Our approach constitutes of elaborating (1) set-based language that covers all the XACML components and establish an intermediate layer to which policies are automatically converted, and (2) policy evaluation module that provides better performance compared to the industrial standard Sun Policy Decision Point (PDP) and its corresponding ameliorations. Experiments have been conducted on real-life and synthetic XACML policies in order to demonstrate the efficiency, relevance and scalability of our proposition. The experimental results explore that SBA-XACML evaluation of large and small sizes policies offers better performance than the current approaches, by a factor ranging between 2.4 and 15 times faster depending on policy size.
引用
收藏
页码:164 / 171
页数:8
相关论文
共 50 条
  • [31] Modeling XACML Security Policies Using Graph Databases
    Paniagua Diez, Fidel
    Vasu, Amrutha Chikkanayakanahalli
    Suarez Touceda, Diego
    Sierra Camara, Jose Maria
    IT PROFESSIONAL, 2017, 19 (06) : 52 - 57
  • [32] Using Microsoft Office InfoPath to Generate XACML Policies
    Sanchez, Manuel
    Lopez, Gabriel
    Gomez-Skarmeta, Antonio F.
    Canovas, Oscar
    E-BUSINESS AND TELECOMMUNICATION NETWORKS, 2008, 9 : 134 - +
  • [33] Managing the lifecycle of XACML delegation policies in federated environments
    Sanchez, Manuel
    Canovas, Oscar
    Lopez, Gabriel
    Gomez-Skarmeta, Antonio F.
    PROCEEDINGS OF THE IFIP TC 11/ 23RD INTERNATIONAL INFORMATION SECURITY CONFERENCE, 2008, : 717 - +
  • [34] ANALYSIS AND VERIFICATION OF XACML POLICIES IN A MEDICAL CLOUD ENVIRONMENT
    Ayache, Meryeme
    Erradi, Mohammed
    Khoumsi, Ahmed
    Freisleben, Bernd
    SCALABLE COMPUTING-PRACTICE AND EXPERIENCE, 2016, 17 (03): : 189 - 205
  • [35] XACML2mCRL2: Automatic transformation of XACML policies into mCRL2 specifications
    Arshad, Hamed
    Horne, Ross
    Johansen, Christian
    Owe, Olaf
    Willemse, Tim A. C.
    SCIENCE OF COMPUTER PROGRAMMING, 2024, 232
  • [36] Deriving XACML policies from business process models
    Wolter, Christian
    Schaad, Andreas
    Meinel, Christoph
    WEB INFORMATION SYSTEMS ENGINEERING - WISE 2007 WORKSHOPS, 2007, 4832 : 142 - +
  • [37] Analyzing XACML policies using answer set programming
    Rezvani, Mohsen
    Rajaratnam, David
    Ignjatovic, Aleksandar
    Pagnucco, Maurice
    Jha, Sanjay
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2019, 18 (04) : 465 - 479
  • [38] A conflict detection approach for XACML policies on hierarchical resources
    Xia, Xiaofeng
    2012 IEEE INTERNATIONAL CONFERENCE ON GREEN COMPUTING AND COMMUNICATIONS, CONFERENCE ON INTERNET OF THINGS, AND CONFERENCE ON CYBER, PHYSICAL AND SOCIAL COMPUTING (GREENCOM 2012), 2012, : 755 - 760
  • [39] Policies towards a more efficient car fleet
    Mandell, Svante
    ENERGY POLICY, 2009, 37 (12) : 5184 - 5191
  • [40] Extending XACML to Express and Enforce Laws and Regulations Privacy Policies
    Alshugran, Tariq
    Dichter, Julius
    Rusu, Amalia
    2015 IEEE LONG ISLAND SYSTEMS, APPLICATIONS AND TECHNOLOGY CONFERENCE (LISAT), 2015,