AccessRefinery: Fast Mining Concise Access Control Intents on Public Cloud
Ning Kang, Peng Zhang, Jianyuan Zhang, Hao Li, Dan Wang, Zhenrong Gu, Weibo Lin, Shibiao Jiang, Zhu He, Xu Du, Longfei Chen, Jun Li, Xiaohong Guan
摘要
Modern cloud applications heavily rely on Identity and Access Management (IAM) services to enforce flexible access control over their data. However, the flexibility comes at a cost: IAM policies are often complex and prone to misconfigurations, leading to risks of data exposure. There is an increasing need to mine a compact set of intents that describe what the policies collectively try to achieve, thereby enabling operators to better understand their policies. However, existing tools on mining access control intent have two limitations: (1) the mining process is slow and even times out on some complex policies; (2) the mined intents are excessive in number and thus still hard to understand. To overcome these, this paper presents AccessRefinery , which can speed up the mining process while reducing the number of intents. The key idea for the speedup is to reduce the redundancy of the multi-round SMT solving, by preprocessing the constraints into bit-vector constraints. For intent reduction, AccessRefinery computes a compact set of intents that can cover the mined intents, by solving a min-set-cover problem. Experiments based on real and synthetic datasets show that AccessRefinery achieves a ∼10–100 × speedup in intent mining, and reduces the number of intents by up to ∼10 ×.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper6
- Block public access: trust safety verification of access control policiesMalik Bouchet, Byron Cook, Bryant Cutler, Anna Druzkina 等FSE 2020 · 被引用 25 次
- Quantifying Permissiveness of Access Control PoliciesWilliam Eiers, Ganesh Sankaran, Albert Li, Emily O'Mahony 等ICSE 2022 · 被引用 15 次
- Even Faster Conflicts and Lazier Reductions for String SolversAndres Nötzli, Andrew Reynolds, Haniel Barbosa, Clark W. Barrett 等CAV 2022 · 被引用 13 次
- NDD: A Decision Diagram for Network VerificationZechun Li, Peng Zhang, Yichi Zhang, Hongkun YangNSDI 2025 · 被引用 11 次
- Quantitative Policy Repair for Access Control on the CloudWilliam Eiers, Ganesh Sankaran, Tevfik BultanISSTA 2023 · 被引用 7 次
相关 Paper
- Relia: Accelerating the Analysis of Cloud Access Control PoliciesDan Wang, Peng Zhang, Zhenrong Gu, Weibo Lin 等ASE 2025
- Automatically Reducing Privilege for Access Control PoliciesLoris D'Antoni, Shuo Ding, Amit Goel, Mathangi Ramesh 等OOPSLA 2024 · 被引用 11 次
- Fixing Privilege Escalations in Cloud Access Control with MaxSAT and Graph Neural NetworksYang Hu, Wenxi Wang, Sarfraz Khurshid, Kenneth L. McMillan 等ASE 2023 · 被引用 4 次
- The Next 700 Policy Miners: A Universal Method for Building Policy MinersCarlos Cotrini, Luca Corinzia, Thilo Weghorn, David A. BasinCCS 2019 · 被引用 19 次
- Automatic Policy Generation for Inter-Service Access Control of MicroservicesXing Li, Yan Chen, Zhiqiang Lin, Xiao Wang 等USENIX Security 2021 · 被引用 64 次
