Quantifying Permissiveness of Access Control Policies
William Eiers, Ganesh Sankaran, Albert Li, Emily O'Mahony, Benjamin Prince, Tevfik Bultan
摘要
Due to ubiquitous use of software services, protecting the confidentiality of private information stored in compute clouds is becoming an increasingly critical problem. Although access control specification languages and libraries provide mechanisms for protecting confidentiality of information, without verification and validation techniques that can assist developers in writing policies, complex policy specifications are likely to have errors that can lead to unintended and unauthorized access to data, possibly with disastrous consequences. In this paper, we present a quantitative and differential policy analysis framework that not only identifies if one policy is more permissive than another policy, but also quantifies the relative permissiveness of access control policies. We quantify permissiveness of policies using a model counting constraint solver. We present a heuristic that transforms constraints extracted from access control policies and significantly improves the model counting performance. We demonstrate the effectiveness of our approach by applying it to policies written in Amazon's AWS Identity and Access Management (IAM) policy language and Microsoft's Azure policy language.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper5
- Cedar: A New Language for Expressive, Fast, Safe, and Analyzable AuthorizationJoseph W. Cutler, Craig Disselkoen, Aaron Eline, Shaobo He 等OOPSLA 2024 · 被引用 28 次
- P-Verifier: Understanding and Mitigating Security Risks in Cloud-based IoT Access PoliciesZe Jin, Luyi Xing, Yiwei Fang, Yan Jia 等CCS 2022 · 被引用 19 次
- Quantitative Policy Repair for Access Control on the CloudWilliam Eiers, Ganesh Sankaran, Tevfik BultanISSTA 2023 · 被引用 7 次
- Better Safe than Sorry: Uncovering the Insecure Resource Management in App-in-App Cloud ServicesYizhe Shi, Zhemin Yang, Dingyi Liu, Kangwei Zhong 等NDSS 2026
- AccessRefinery: Fast Mining Concise Access Control Intents on Public CloudNing Kang, Peng Zhang, Jianyuan Zhang, Hao Li 等FSE 2026
相关 Paper
- Automatically Reducing Privilege for Access Control PoliciesLoris D'Antoni, Shuo Ding, Amit Goel, Mathangi Ramesh 等OOPSLA 2024 · 被引用 11 次
- Detecting Multi-Step IAM Attacks in AWS Environments via Model CheckingIlia Shevrin, Oded MargalitUSENIX Security 2023
- GRASP: Hardening Serverless Applications through Graph Reachability Analysis of Security PoliciesIsaac Polinsky, Pubali Datta, Adam Bates, William EnckWWW 2024 · 被引用 15 次
- Relia: Accelerating the Analysis of Cloud Access Control PoliciesDan Wang, Peng Zhang, Zhenrong Gu, Weibo Lin 等ASE 2025
- Block public access: trust safety verification of access control policiesMalik Bouchet, Byron Cook, Bryant Cutler, Anna Druzkina 等FSE 2020 · 被引用 25 次
