Towards Continuous Access Control Validation and Forensics
Chengcheng Xiang, Yudong Wu, Bingyu Shen, Mingyao Shen, Haochen Huang, Tianyin Xu, Yuanyuan Zhou, Cindy Moore, Xinxin Jin, Tianwei Sheng
Abstract
Access control is often reported to be "profoundly broken" in real-world practices due to prevalent policy misconfigurations introduced by system administrators (sysadmins). Given the dynamics of resource and data sharing, access control policies need to be continuously updated. Unfortunately, to err is human-sysadmins often make mistakes such as over-granting privileges when changing access control policies. With today's limited tooling support for continuous validation, such mistakes can stay unnoticed for a long time until eventually being exploited by attackers, causing catastrophic security incidents. We present P-DIFF, a practical tool for monitoring access control behavior to help sysadmins early detect unintended access control policy changes and perform postmortem forensic analysis upon security attacks. P-DIFF continuously monitors access logs and infers access control policies from them. To handle the challenge of policy evolution, we devise a novel time-changing decision tree to effectively represent access control policy changes, coupled with a new learning algorithm to infer the tree from access logs. P-DIFF provides sysadmins with the inferred policies and detected changes to assist the following two tasks: (1) validating whether the access control changes are intended or not; (2) pinpointing the historical changes responsible for a given security attack. We evaluate P-DIFF with a variety of datasets collected from five real-world systems, including two from industrial companies. P-DIFF can detect 86%-100% of access control policy changes with an average precision of 89%. For forensic analysis, P-DIFF can pinpoint the root-cause change that permits the target access in 85%-98% of the evaluated cases.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext dfef0e4d-2922-4562-8759-d63d44ae473cCited by top-tier papers15
- Automatic Policy Generation for Inter-Service Access Control of MicroservicesXing Li, Yan Chen, Zhiqiang Lin, Xiao Wang et al.USENIX Security 2021 · 64 citations
- Testing Configuration Changes in Context to Prevent Production FailuresXudong Sun, Runxiang Cheng, Jianyan Chen, Elaine Ang et al.OSDI 2020 · 61 citations
- Test-case prioritization for configuration testingRunxiang Cheng, Lingming Zhang, Darko Marinov, Tianyin XuISSTA 2021 · 34 citations
- Static detection of silent misconfigurations with deep interaction analysisJialu Zhang, Ruzica Piskac, Ennan Zhai, Tianyin XuOOPSLA 2021 · 30 citations
- PracExtractor: Extracting Configuration Good Practices from Manuals to Detect Server MisconfigurationsChengcheng Xiang, Haochen Huang, Andrew Yoo, Yuanyuan Zhou et al.USENIX ATC 2020 · 24 citations
Related papers
- Improving Logging to Reduce Permission Over-Granting MistakesBingyu Shen, Tianyi Shan, Yuanyuan ZhouUSENIX Security 2023
- Forensic Analysis in Access Control: Foundations and a Case-Study from PracticeNahid Juma, Xiaowei Huang, Mahesh TripunitaraCCS 2020 · 2 citations
- Automatically Reducing Privilege for Access Control PoliciesLoris D'Antoni, Shuo Ding, Amit Goel, Mathangi Ramesh et al.OOPSLA 2024 · 11 citations
- Multiview: Finding Blind Spots in Access-Deny Issues DiagnosisBingyu Shen, Tianyi Shan, Yuanyuan ZhouUSENIX Security 2023
- Cost-effective Attack Forensics by Recording and Correlating File System ChangesLe Yu, Yapeng Ye, Zhuo Zhang, Xiangyu ZhangUSENIX Security 2024 · 5 citations
