Affiliation:
1. University of Huddersfield, Queensgate, Huddersfield, West Yorkshire, UK
Abstract
There any many different access-control systems, yet a commonality is that they provide flexible mechanisms to enforce different access levels. Their importance in organisations to adequately restrict resources, coupled with their use in a dynamic environment, mandates the need to routinely perform policy analysis. The aim of performing analysis is often to identify potential problematic permissions, which have the potential to be exploited and could result in data theft and unintended modification. There is a vast body of published literature on analysing access-control systems, yet as performing analysis has a strong end-user motivation and is grounded in security challenges faced in real-world systems, it is important to understand how research is developing, what are the common themes of interest, and to identify key challenges that should be addressed in future work. To the best of the authors’ knowledge, no survey has been performed to gain an understanding of empirical access-control analysis, focussing on how techniques are evaluated and how they align to the needs of real-world analysis tasks. This article provides a systematic literature review, identifying and summarising key works. Key findings are identified and discussed as areas of future work.
Publisher
Association for Computing Machinery (ACM)
Subject
General Computer Science,Theoretical Computer Science
Reference111 articles.
1. A novel conflict detection method for ABAC security policies
2. WorSE: A Workbench for Model-based Security Engineering
3. Extensible access control markup language (XACML) version 1.0;Anderson Anne;OASIS,2003
4. A tool for access control policy validation;Aqmocanuib Muhammad;J. Internet Technol.,2018
5. Alessandro Armando and Silvio Ranise. 2010. Automated symbolic analysis of ARBAC-policies. In Proceedings of the International Workshop on Security and Trust Management. Springer, 17–34.
Cited by
15 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献