A framework for security assurance of access control enforcement code

被引:8
|
作者
Pavlich-Mariscal, Jaime A. [1 ]
Demurjian, Steven A. [2 ]
Michel, Laurent D. [2 ]
机构
[1] Univ Catolica Norte, Dept Ingn Sistemas & Computac, Angamos 0610, Antofagasta, Chile
[2] Univ Connecticut, Dept Comp Sci & Engn, Unit 2155, Storrs, CT 06269 USA
关键词
Security assurance; Access control; Formal methods; UML;
D O I
10.1016/j.cose.2010.03.004
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Modeling of access control policies, along with their implementation in code, must be an integral part of the software development process, to ensure that the proper level of security in an application is attained. Previous work of the authors in this area yielded a framework that incorporates access control at the design and code levels, through a set of new extensions to UML and a set of approaches to enfoce access control in an application (Pavlich-Mariscal et al., 2010). An essential property of the code that has not been addressed by that framework is security assurance, which, in the context of this research, is to insure that the application code behaves consistently with the access control policy. This paper proposes a security assurance mechanism that formalizes the application behavior using labeled transition systems and structural operational semantics (Plotkin, 1981). Simulation relations (Milner, 1971) are used to demonstrate the correctness of the access control code with respect to the design. To validate the approach, this paper proves correctness of two access control enforcement mechanisms that are part of our case study: a basic approach to implement access control in code and an aspect-oriented approach. (C) 2010 Elsevier Ltd. All rights reserved.
引用
收藏
页码:770 / 784
页数:15
相关论文
共 50 条
  • [41] Security network policy enforcement through a SDN framework
    Berardi, Davide
    Callegati, Franco
    Melis, Andrea
    Prandini, Marco
    [J]. 2018 28TH INTERNATIONAL TELECOMMUNICATION NETWORKS AND APPLICATIONS CONFERENCE (ITNAC), 2018, : 97 - 100
  • [42] A logical framework for security enforcement in CapBasED-AMS
    Hung, PCK
    Karlapalem, K
    [J]. INTERNATIONAL JOURNAL OF COOPERATIVE INFORMATION SYSTEMS, 1997, 6 (3-4) : 367 - 392
  • [43] A novel and efficient framework for in-vehicle security enforcement
    Haddaji, Achref
    Ayed, Samiha
    Fourati, Lamia Chaari
    [J]. AD HOC NETWORKS, 2024, 158
  • [44] Security and source code access: Issues and realities
    Lipner, SB
    [J]. 2000 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, PROCEEDINGS, 2000, : 124 - 125
  • [45] GEODAC: A Data Assurance Policy Specification and Enforcement Framework for Outsourced Services
    Li, Jun
    Stephenson, Bryan
    Motahari-Nezhad, Hamid R.
    Singhal, Sharad
    [J]. IEEE TRANSACTIONS ON SERVICES COMPUTING, 2011, 4 (04) : 340 - 354
  • [46] Security policies definition and enforcement utilizing policy control function framework in 5G
    Gomez, German Peinado
    Batalla, Jordi Mongay
    Miche, Yoan
    Holtmanns, Silke
    Mavromoustakis, Constandinos X.
    Mastorakis, George
    Haider, Noman
    [J]. COMPUTER COMMUNICATIONS, 2021, 172 : 226 - 237
  • [47] A Trustworthy Usage Control Enforcement Framework
    Neisse, Ricardo
    Pretschner, Alexander
    Di Giacomo, Valentina
    [J]. INTERNATIONAL JOURNAL OF MOBILE COMPUTING AND MULTIMEDIA COMMUNICATIONS, 2013, 5 (03) : 34 - 49
  • [48] ACTkit: A Framework for the Definition and Enforcement of Role, Content and Context-based Access Control Policies
    Betarte, G.
    Gatto, A.
    Martinez, R.
    Zipitria, F.
    [J]. IEEE LATIN AMERICA TRANSACTIONS, 2012, 10 (03) : 1742 - 1751
  • [49] Framework for security analysis and access control in a Distributed Service Medical Imaging Network
    Greenshields, IR
    Yang, ZH
    [J]. INFORMATION SECURITY FOR GLOBAL INFORMATION INFRASTRUCTURES, 2000, 47 : 391 - 400
  • [50] A Sequence-Based Access Control Framework for Reliable Security Management in Clouds
    Moghaddam, Faraz Fatemi
    Emadinia, Tayyebe
    Wieder, Philipp
    Yahyapour, Ramin
    [J]. 2018 IEEE 6TH INTERNATIONAL CONFERENCE ON FUTURE INTERNET OF THINGS AND CLOUD (FICLOUD 2018), 2018, : 108 - 113