CASPR: Context-Aware Security Policy Recommendation
Lifang Xiao, Hanyu Wang, Aimin Yu, Lixin Zhao, Dan Meng
摘要
—Nowadays, SELinux has been widely used to provide flexible mandatory access control and security policies are critical to maintain the security of operating systems. Strictly speaking, all access requests must be restricted by appropriate policy rules to satisfy the functional requirements of the software or application. However, manually configuring security policy rules is an error-prone and time-consuming task that often requires expert knowledge. Therefore, it is a challenging task to recommend policy rules without anomalies effectively due to the numerous policy rules and the complexity of semantics. The majority of previous research mined information from policies to recommend rules but did not apply to the newly defined types without any rules. In this paper, we propose a context-aware security policy recommendation (CASPR) method that can automatically analyze and refine security policy rules. Context-aware information in CASPR includes policy rules, file locations, audit logs, and attribute information. According to these context-aware information, multiple features are extracted to calculate the similarity of privilege sets. Based on the calculation results, CASPR clusters types by the K-means model and then recommends rules automatically. The method automatically detects anomalies in security policy, namely, constraint conflicts, policy inconsistencies, and permission incompleteness. Further, the detected anomalous policies are refined so that the authorization rules can be effectively enforced. The experiment results confirm the feasibility of the proposed method for recommending effective rules for different versions of policies. We demonstrate the effectiveness of clustering by CASPR and calculate the contribution of each context-aware feature based on SHAP. CASPR not only recommends rules for newly defined types based on context-aware information but also enhances the accuracy of security policy recommendations for existing types, compared to other rule recommendation models. CASPR has an average accuracy of 91.582% and F1-score of 93.761% in recommending rules. Further, three kinds of anomalies in the policies can be detected and automatically repaired. We employ CASPR in multiple operating systems to illustrate the universality. The research has significant implications for security policy recommendation and provides a novel method for policy analysis with great potential.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper10
- Kratos: Discovering Inconsistent Security Policy Enforcement in the Android FrameworkYuru Shao, Qi Alfred Chen, Zhuoqing Morley Mao, Jason Ott 等NDSS 2016 · 被引用 85 次
- Automatic Policy Generation for Inter-Service Access Control of MicroservicesXing Li, Yan Chen, Zhiqiang Lin, Xiao Wang 等USENIX Security 2021 · 被引用 64 次
- Towards Continuous Access Control Validation and ForensicsChengcheng Xiang, Yudong Wu, Bingyu Shen, Mingyao Shen 等CCS 2019 · 被引用 48 次
- PolicyChecker: Analyzing the GDPR Completeness of Mobile Apps' Privacy PoliciesAnhao Xiang, Weiping Pei, Chuan YueCCS 2023 · 被引用 24 次
- SEPAL: Towards a Large-scale Analysis of SEAndroid Policy CustomizationDongsong Yu, Guangliang Yang, Guozhu Meng, Xiaorui Gong 等WWW 2021 · 被引用 10 次
相关 Paper
- Poirot: Probabilistically Recommending Protections for the Android FrameworkZeinab El-Rewini, Zhuo Zhang, Yousra AaferCCS 2022 · 被引用 6 次
- The Next 700 Policy Miners: A Universal Method for Building Policy MinersCarlos Cotrini, Luca Corinzia, Thilo Weghorn, David A. BasinCCS 2019 · 被引用 19 次
- Automatically Reducing Privilege for Access Control PoliciesLoris D'Antoni, Shuo Ding, Amit Goel, Mathangi Ramesh 等OOPSLA 2024 · 被引用 11 次
- A NEW HOPE: Contextual Privacy Policies for Mobile Applications and An Approach Toward Automated GenerationShidong Pan, Zhen Tao, Thong Hoang, Dawen Zhang 等USENIX Security 2024 · 被引用 24 次
- Improving Logging to Reduce Permission Over-Granting MistakesBingyu Shen, Tianyi Shan, Yuanyuan ZhouUSENIX Security 2023
