Automated Analysis of Semantic-Aware Access Control Policies: a Logic-Based Approach

被引:1
|
作者
Armando, Alessandro [1 ,2 ]
Carbone, Roberto [2 ]
Ranise, Silvio [2 ]
机构
[1] Univ Genoa, DIST, AI Lab, Viale Causa 13, I-16145 Genoa, Italy
[2] FBK, Secur & Trust Unit, I-38123 Trento, Italy
关键词
semantic-aware access control; automatic analysis; logic-based methods;
D O I
10.1109/ICSC.2011.74
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
As the number and sophistication of on-line applications increase, there is a growing concern on how access to sensitive resources (e.g., personal health records) is regulated. Since ontologies can support the definition of fine-grained policies as well as the combination of heterogeneous policies, semantic technologies are expected to play an important role in this context. But understanding the implications of the access control policies of the needed complexity goes beyond the ability of a security administrator. Automatic support to the analysis of access control policies is therefore needed. In this paper we present an automatic analysis technique for access control policies that reduces the reachability problem for access control policies to satisfiability problems in a decidable fragment of first-order logic for which efficient solvers exist. We illustrate the application of our technique on an access control model inspired by a Personal Health Application of real-world complexity.
引用
收藏
页码:356 / 363
页数:8
相关论文
共 50 条
  • [11] Protecting personal data with various granularities: A logic-based access control approach
    Purevjii, BO
    Aritsugi, M
    Imai, S
    Kanamori, Y
    Pancake, CM
    [J]. COMPUTATIONAL INTELLIGENCE AND SECURITY, PT 2, PROCEEDINGS, 2005, 3802 : 548 - 553
  • [12] Constraining Credential Usage in Logic-Based Access Control
    Bauer, Lujo
    Jia, Limin
    Sharma, Divya
    [J]. 2010 23RD IEEE COMPUTER SECURITY FOUNDATIONS SYMPOSIUM (CSF), 2010, : 154 - 168
  • [13] Semantic-aware Comment Analysis Approach for API Permission Mapping on Android
    Shim, Hyunseok
    Jung, Souhwan
    [J]. ACM International Conference Proceeding Series, 2020, : 61 - 69
  • [14] Semantic-aware Comment Analysis Approach for API Permission Mapping on Android
    Shim, Hyunseok
    Jung, Souhwan
    [J]. 2020 4TH INTERNATIONAL CONFERENCE ON NATURAL LANGUAGE PROCESSING AND INFORMATION RETRIEVAL, NLPIR 2020, 2020, : 61 - 69
  • [15] Automated Analysis of Access Control Policies Based on Model Checking
    Truong A.
    [J]. SN Computer Science, 2020, 1 (6)
  • [16] Logic and logic-based control
    Hongsheng QI
    [J]. Control Theory and Technology, 2008, (01) : 26 - 36
  • [17] Logic and logic-based control
    Qi H.
    Cheng D.
    [J]. Journal of Control Theory and Applications, 2008, 6 (01): : 26 - 36
  • [18] A Semantic-Aware Approach for Automatic Cloud Services Composition
    Naji, Hasan A. H.
    Wu, Chao Zhong
    Gao, Shu
    [J]. INTERNATIONAL JOURNAL OF GRID AND DISTRIBUTED COMPUTING, 2016, 9 (08): : 181 - 195
  • [19] LOGIC-BASED CONFIGURATION WITH A SEMANTIC NETWORK
    SEARLS, DB
    NORTON, LM
    [J]. JOURNAL OF LOGIC PROGRAMMING, 1990, 8 (1-2): : 53 - 73
  • [20] A logic-based approach to program flow analysis
    Mooly Sagiv
    Nissim Francez
    Michael Rodeh
    Reinhard Wilhelm
    [J]. Acta Informatica, 1998, 35 : 457 - 504