Federated access control and workflow enforcement in systems configuration

  • Authors:
  • Bart Vanbrabant;Thomas Delaet;Wouter Joosen

  • Affiliations:
  • DistriNet, Dept. of Computer Science, K.U.Leuven, Belgium;DistriNet, Dept. of Computer Science, K.U.Leuven, Belgium;DistriNet, Dept. of Computer Science, K.U.Leuven, Belgium

  • Venue:
  • LISA'09 Proceedings of the 23rd conference on Large installation system administration
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

Every organization with more than a few system administrators has policies in place. These policies define who is allowed to change what aspects of the configuration of a computer infrastructure. Althoughmany system configuration tools are available for automating configuration changes in an infrastructure, very little work has been done to enforce the policies dealing with access control and workflow of configuration changes. In this paper, we present ACHEL. ACHEL makes it possible to integrate fine-grained access control into existing configuration tools and to enforce an organization's configuration changes workflow. In addition, we prototype ACHEL on a popular configuration tool and demonstrate its capabilities in two case studies.