Abductive analysis of administrative policies in rule-based access control

  • Authors:
  • Puneet Gupta;Scott D. Stoller;Zhongyuan Xu

  • Affiliations:
  • Department of Computer Science, Stony Brook University;Department of Computer Science, Stony Brook University;Department of Computer Science, Stony Brook University

  • Venue:
  • ICISS'11 Proceedings of the 7th international conference on Information Systems Security
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

In large organizations, the access control policy is managed by multiple users (administrators). An administrative policy specifies how each user may change the policy. The consequences of an administrative policy are often non-obvious, because sequences of changes by different users may interact in unexpected ways. Administrative policy analysis helps by answering questions such as user-permission reachability, which asks whether specified users can together change the policy in a way that achieves a specified goal, namely, granting a specified permission to a specified user.