The need for application-aware access control evaluation

  • Authors:
  • William C. Garrison;Adam J. Lee;Timothy L. Hinrichs

  • Affiliations:
  • University of Pittsburgh, Pittsburgh, PA, USA;University of Pittsburgh, Pittsburgh, PA, USA;University of Illinois at Chicago, Chicago, IL, USA

  • Venue:
  • Proceedings of the 2012 workshop on New security paradigms
  • Year:
  • 2012

Quantified Score

Hi-index 0.00

Visualization

Abstract

Access control is an area where one size does not fit all. However, previous work in access control has focused solely on expressiveness as an absolute measure. Thus, we discuss and justify the need for a new type of evaluation framework for access control, one that is application-aware. To this end, we apply previous work in access control evaluation, as well as lessons learned from evaluation frameworks used in other domains. We describe the analysis components required by such a framework, the challenges involved in building it, and our preliminary work in realizing this ambitious goal. We then theorize about other areas within the security domain that display a similar absence of such evaluation tools, and consider ways in which we can adapt our framework to analyze these broader types of security workloads.