Analysis of access control policy updates through narrowing - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2016

Analysis of access control policy updates through narrowing

Résumé

Administration of access control policies is a difficult task, especially in large organizations. We consider the problem of detecting whether administrative actions can yield in policies where some security goals are compromised. In particular, we are interested in problems generated by modifications --- such as adding/deleting elements to/from the set of possible users or permissions --- of policies specified as term-rewrite systems. We propose to use rewriting techniques to compare the behaviors of the modified version and the original version of the policy. More precisely, we use narrowing to compute counter-examples to the equivalence of rewrite-based policies. We prove that our technique provides a sound and complete way to recursively enumerate the set of counter-examples, even when this set is not finite, or when a mistake of the administrator makes one or both systems non-terminating.
Fichier non déposé

Dates et versions

hal-01452928 , version 1 (02-02-2017)

Identifiants

  • HAL Id : hal-01452928 , version 1

Citer

Clara Bertolissi, Jean-Marc Talbot, Didier Villevalois. Analysis of access control policy updates through narrowing. Proceedings of the 18th International Symposium on Principles and Practice of Declarative Programming, Sep 2016, Edinburgh, United Kingdom. pp.Pages 62-75. ⟨hal-01452928⟩
43 Consultations
0 Téléchargements

Partager

Gmail Facebook X LinkedIn More