2018
DOI: 10.1145/3209668
|View full text |Cite
|
Sign up to set email alerts
|

The Challenge of Access Control Policies Quality

Abstract: Access Control policies allow one to control data sharing among multiple subjects. For high assurance data security, it is critical that such policies be fit for their purpose. In this paper we introduce the notion of “policy quality” and elaborate on its many dimensions, such as consistency, completeness, and minimality. We introduce a framework supporting the analysis of policies with respect to the introduced quality dimensions and elaborate on research challenges, including policy analysis for large-scale … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
10
0

Year Published

2019
2019
2024
2024

Publication Types

Select...
4
3
1

Relationship

1
7

Authors

Journals

citations
Cited by 17 publications
(10 citation statements)
references
References 15 publications
0
10
0
Order By: Relevance
“…Finally, accessibility and acquisition (security) are present in Wang and Strong [75] and Ge et al [36]. The use of digital technologies in the construction industry has increased the speed of work, improved communication, allowed for faster access [8] to common data and a decrease in the number of mistakes in documentation [62]. Moreover, the advent of BIM in the construction industry has leveraged the use of digital information which implies improved information flows [51] and decision-making in the design process [65].…”
Section: Incentivesmentioning
confidence: 99%
“…Finally, accessibility and acquisition (security) are present in Wang and Strong [75] and Ge et al [36]. The use of digital technologies in the construction industry has increased the speed of work, improved communication, allowed for faster access [8] to common data and a decrease in the number of mistakes in documentation [62]. Moreover, the advent of BIM in the construction industry has leveraged the use of digital information which implies improved information flows [51] and decision-making in the design process [65].…”
Section: Incentivesmentioning
confidence: 99%
“…2) Quality Assessment and Validation of Policies: The goal of the PCP component of the framework is to check the quality and validity of the generated policies received internally, or of external policies shared by other AMSs in a collaborative environment. Quality of policies can be checked by the Quality component inside the PCP by considering different policy metrics and policy quality requirements such as consistency, completeness, relevance, and minimality [14].…”
Section: A Key Components Of Agenpmentioning
confidence: 99%
“…"Low quality" examples include inconsistent responses to similar requests and requests associated with irrelevant responses which do not reflect appropriate decisions of a policies (i.e., 'not applicable' decision for XACML policies). Formal definitions of "low quality" examples can be adapted from the definitions of "low quality" policies by Bertino et al [14], [31]. These formal definitions enable analyzing policies [31], [32].…”
Section: Access Control Policiesmentioning
confidence: 99%
See 1 more Smart Citation
“…All the combined attacks build an attack path that can be used to retrace the attack. Additionally, the specification of dynamic access control policies, such as attribute-based access control (ABAC) [5], is complicated [6] because of the range of possible values, and it is hard to estimate the impact of access control policies on the confidentiality of the system [7]. This holds especially for more subtle consequences like enabling a malicious user to propagate easier through the system.…”
Section: Introductionmentioning
confidence: 99%