Towards Continuous Access Control Validation and Forensics
Chengcheng Xiang, Yudong Wu, Bingyu Shen, Mingyao Shen, Haochen Huang, Tianyin Xu, Yuanyuan Zhou, Cindy Moore, Xinxin Jin, Tianwei Sheng
摘要
Access control is often reported to be "profoundly broken" in real-world practices due to prevalent policy misconfigurations introduced by system administrators (sysadmins). Given the dynamics of resource and data sharing, access control policies need to be continuously updated. Unfortunately, to err is human-sysadmins often make mistakes such as over-granting privileges when changing access control policies. With today's limited tooling support for continuous validation, such mistakes can stay unnoticed for a long time until eventually being exploited by attackers, causing catastrophic security incidents. We present P-DIFF, a practical tool for monitoring access control behavior to help sysadmins early detect unintended access control policy changes and perform postmortem forensic analysis upon security attacks. P-DIFF continuously monitors access logs and infers access control policies from them. To handle the challenge of policy evolution, we devise a novel time-changing decision tree to effectively represent access control policy changes, coupled with a new learning algorithm to infer the tree from access logs. P-DIFF provides sysadmins with the inferred policies and detected changes to assist the following two tasks: (1) validating whether the access control changes are intended or not; (2) pinpointing the historical changes responsible for a given security attack. We evaluate P-DIFF with a variety of datasets collected from five real-world systems, including two from industrial companies. P-DIFF can detect 86%-100% of access control policy changes with an average precision of 89%. For forensic analysis, P-DIFF can pinpoint the root-cause change that permits the target access in 85%-98% of the evaluated cases.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper15
- Automatic Policy Generation for Inter-Service Access Control of MicroservicesXing Li, Yan Chen, Zhiqiang Lin, Xiao Wang 等USENIX Security 2021 · 被引用 64 次
- Testing Configuration Changes in Context to Prevent Production FailuresXudong Sun, Runxiang Cheng, Jianyan Chen, Elaine Ang 等OSDI 2020 · 被引用 61 次
- Test-case prioritization for configuration testingRunxiang Cheng, Lingming Zhang, Darko Marinov, Tianyin XuISSTA 2021 · 被引用 34 次
- Static detection of silent misconfigurations with deep interaction analysisJialu Zhang, Ruzica Piskac, Ennan Zhai, Tianyin XuOOPSLA 2021 · 被引用 30 次
- PracExtractor: Extracting Configuration Good Practices from Manuals to Detect Server MisconfigurationsChengcheng Xiang, Haochen Huang, Andrew Yoo, Yuanyuan Zhou 等USENIX ATC 2020 · 被引用 24 次
相关 Paper
- Improving Logging to Reduce Permission Over-Granting MistakesBingyu Shen, Tianyi Shan, Yuanyuan ZhouUSENIX Security 2023
- Forensic Analysis in Access Control: Foundations and a Case-Study from PracticeNahid Juma, Xiaowei Huang, Mahesh TripunitaraCCS 2020 · 被引用 2 次
- Automatically Reducing Privilege for Access Control PoliciesLoris D'Antoni, Shuo Ding, Amit Goel, Mathangi Ramesh 等OOPSLA 2024 · 被引用 11 次
- Multiview: Finding Blind Spots in Access-Deny Issues DiagnosisBingyu Shen, Tianyi Shan, Yuanyuan ZhouUSENIX Security 2023
- Cost-effective Attack Forensics by Recording and Correlating File System ChangesLe Yu, Yapeng Ye, Zhuo Zhang, Xiangyu ZhangUSENIX Security 2024 · 被引用 5 次
