Scalable and Precise Automated Analysis of Administrative Temporal Role-Based Access Control

被引:13
|
作者
Ranise, Silvio [1 ]
Truong, Anh [1 ]
Armando, Alessandro [1 ]
机构
[1] FBK Irst, Secur & Trust, Trento, Italy
关键词
Administrative Access Control; Temporal Role-Based Access Control; Automated Safety Analysis; SYMBOLIC ANALYSIS;
D O I
10.1145/2613087.2613102
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Extensions of Role-Based Access Control (RBAC) policies taking into account contextual information (such as time and space) are increasingly being adopted in real-world applications. Their administration is complex since they must satisfy rapidly evolving needs. For this reason, automated techniques to identify unsafe sequences of administrative actions (i.e. actions generating policies by which a user can acquire permissions that may compromise some security goals) are fundamental tools in the administrator's tool-kit. In this paper, we propose a precise and scalable automated analysis technique for the safety of administrative temporal RBAC policies. Our approach is to translate safety problems for this kind of policy to (decidable) reachability problems of a certain class of symbolic transition systems. The correctness of the translation allows us to design a precise analysis technique for the safety of administrative RBAC policies with a finite but unknown number of users. For scalability, we present a heuristics that allows us to reduce the set of administrative actions without losing the precision of the analysis. An extensive experimental analysis confirms the scalability and precision of the approach also in comparison with a recent analysis technique developed for the same class of temporal RBAC policies.
引用
收藏
页码:103 / 114
页数:12
相关论文
共 50 条
  • [1] Scalable automated symbolic analysis of administrative role-based access control policies by SMT solving
    Armando, Alessandro
    Ranise, Silvio
    [J]. JOURNAL OF COMPUTER SECURITY, 2012, 20 (04) : 309 - 352
  • [2] AMTRAC: An administrative model for temporal role-based access control
    Sharma, Manisha
    Sural, Shamik
    Vaidya, Jaideep
    Atluri, Vijayalakshmi
    [J]. COMPUTERS & SECURITY, 2013, 39 : 201 - 218
  • [3] Policy analysis for Administrative Role-Based Access Control
    Sasturkar, Amit
    Yang, Ping
    Stoller, Scott D.
    Ramakrishnan, C. R.
    [J]. THEORETICAL COMPUTER SCIENCE, 2011, 412 (44) : 6208 - 6234
  • [4] Automated and Efficient Analysis of Role-Based Access Control with Attributes
    Armando, Alessandro
    Ranise, Silvio
    [J]. DATA AND APPLICATIONS SECURITY AND PRIVACY XXVI, 2012, 7371 : 25 - 40
  • [5] Symbolic reachability analysis for parameterized administrative role-based access control
    Stoller, Scott D.
    Yang, Ping
    Gofman, Mikhail I.
    Ramakrishnan, C. R.
    [J]. COMPUTERS & SECURITY, 2011, 30 (2-3) : 148 - 164
  • [6] Cree: A Performant Tool for Safety Analysis of Administrative Temporal Role-Based Access Control (ATRBAC) Policies
    Shahen, Jonathan
    Niu, Jianwei
    Tripunitara, Mahesh, V
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2021, 18 (05) : 2349 - 2364
  • [7] Security Analysis of Administrative Role-Based Access Control Policies with Contextual Information
    Khai Kim Quoc Dinh
    Tuan Duc Tran
    Anh Truong
    [J]. FUTURE DATA AND SECURITY ENGINEERING, 2017, 10646 : 243 - 261
  • [8] VAC - Verifier of Administrative Role-Based Access Control Policies
    Ferrara, Anna Lisa
    Madhusudan, P.
    Nguyen, Truc L.
    Parlato, Gennaro
    [J]. COMPUTER AIDED VERIFICATION, CAV 2014, 2014, 8559 : 184 - 191
  • [9] Planning User Assignment in Administrative Role-Based Access Control
    Huang, Wei
    Yang, Yang
    [J]. 2009 ISECS INTERNATIONAL COLLOQUIUM ON COMPUTING, COMMUNICATION, CONTROL, AND MANAGEMENT, VOL IV, 2009, : 615 - +
  • [10] Scalable and Efficient Reasoning for Enforcing Role-Based Access Control
    Cadenhead, Tyrone
    Kantarcioglu, Murat
    Thuraisingham, Bhavani
    [J]. DATA AND APPLICATIONS SECURITY AND PRIVACY XXIV, PROCEEDINGS, 2010, 6166 : 209 - 224