Detecting Incorrect Uses of Combining Algorithms in XACML 3.0 Policies

被引:2
|
作者
Xu, Dianxiang [1 ]
Shen, Ning [1 ]
Zhang, Yunpeng [1 ,2 ]
机构
[1] Boise State Univ, Dept Comp Sci, Boise, ID 83725 USA
[2] Univ Houston, Dept Informat & Logist Technol, Houston, TX 77204 USA
基金
美国国家科学基金会;
关键词
Combining algorithm; constraint solving; fault-based testing; XACML; VERIFICATION;
D O I
10.1142/S021819401540032X
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
With the increasing complexity of software, new access control methods have emerged to deal with attribute-based authorization. As a standard language for specifying attribute-based access control policies, XACML offers a number of rule and policy combining algorithms to meet different needs of policy composition. Due to their variety and complexity, however, it is not uncommon to apply combining algorithms incorrectly, which can lead to unauthorized access or denial of service. To solve this problem, this paper presents a fault-based testing approach for revealing incorrect combining algorithms in XACML 3.0 policies. The theoretical foundation of this approach relies on the formalization of semantic differences between rule combining algorithms and between policy combining algorithms. It allows the use of a constraint solver for generating queries to which a given policy produces different responses than its combining algorithm-based mutants. Such queries can determine whether or not the given combining algorithm is used correctly. Our empirical studies using various XACML policies have demonstrated that our approach is effective.
引用
收藏
页码:1551 / 1571
页数:21
相关论文
共 10 条
  • [1] Formalizing Semantic Differences between Combining Algorithms in XACML 3.0 Policies
    Xu, Dianxiang
    Zhang, Yunpeng
    Shen, Ning
    2015 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE SECURITY AND RELIABILITY (QRS 2015), 2015, : 163 - 172
  • [2] Semantics-based approach for detecting flaws, conflicts and redundancies in XACML policies
    Jebbaoui, Hussein
    Mourad, Azzam
    Otrok, Hadi
    Haraty, Ramzi
    COMPUTERS & ELECTRICAL ENGINEERING, 2015, 44 : 91 - 103
  • [3] Security Enhancement in Web Services by Detecting and Correcting Anomalies in XACML Policies at Design Level
    Priyadharshini, M.
    Yowan, J.
    Baskaran, R.
    SECURITY IN COMPUTING AND COMMUNICATIONS, 2014, 467 : 120 - 135
  • [4] Detecting convergence in genetic algorithms with decreasing mutation policies
    García, SE
    Saad, M
    Akhrif, O
    PROCEEDINGS OF THE IASTED INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE, 2005, : 369 - 374
  • [5] Using the Decision Support Algorithms Combining Different Security Policies
    Belim, S. V.
    Bogachenko, N. F.
    Kabanov, A. N.
    Rakitskiy, Yu. S.
    2016 DYNAMICS OF SYSTEMS, MECHANISMS AND MACHINES (DYNAMICS), 2016,
  • [6] Operation Policies through Dynamic Programming and Genetic Algorithms, for a Reservoir with Irrigation and Water Supply Uses
    Rosalva Mendoza Ramírez
    Maritza Liliana Arganis Juárez
    Ramón Domínguez Mora
    Luis Daniel Padilla Morales
    Óscar Arturo Fuentes Mariles
    Alejandro Mendoza Reséndiz
    Eliseo Carrizosa Elizondo
    Rafael Bernardo Carmona Paredes
    Water Resources Management, 2021, 35 : 1573 - 1586
  • [7] Operation Policies through Dynamic Programming and Genetic Algorithms, for a Reservoir with Irrigation and Water Supply Uses
    Mendoza Ramirez, Rosalva
    Arganis Juarez, Maritza Liliana
    Dominguez Mora, Ramon
    Padilla Morales, Luis Daniel
    Fuentes Mariles, Oscar Arturo
    Mendoza Resendiz, Alejandro
    Carrizosa Elizondo, Eliseo
    Carmona Paredes, Rafael Bernardo
    WATER RESOURCES MANAGEMENT, 2021, 35 (05) : 1573 - 1586
  • [8] A hybrid model combining mode decomposition and deep learning algorithms for detecting TP in urban sewer networks
    Zhang, Yituo
    Li, Chaolin
    Jiang, Yiqi
    Zhao, Ruobin
    Yan, Kefen
    Wang, Wenhui
    APPLIED ENERGY, 2023, 333
  • [9] Markov Model Combining Handover Algorithms with Call Admission Control Policies in Vehicular RoF Networks at 60 GHz
    Tselikas, Nikolaos D.
    2016 18TH INTERNATIONAL CONFERENCE ON TRANSPARENT OPTICAL NETWORKS (ICTON), 2016,
  • [10] Combining multi-scale textural features from the panchromatic bands of high spatial resolution images with ANN and MLC classification algorithms to extract urban land uses
    Saboori, Mojtaba
    Torahi, Ali Asghar
    Bakhtyari, Hamid Reza Riyahi
    INTERNATIONAL JOURNAL OF REMOTE SENSING, 2019, 40 (22) : 8608 - 8634