Catalog Home Page

Techniques for automating policy specification for application-oriented access controls

Schreuders, Z.C., Payne, C. and McGill, T.J. (2011) Techniques for automating policy specification for application-oriented access controls. In: Sixth International Conference on Availability, Reliability and Security (AReS 2011), 22 - 26 August 2011, Vienna, Austria.

[img]
Preview
PDF - Authors' Version
Download (165kB) | Preview
    Link to Published Version: http://dx.doi.org/10.1109/ARES.2011.47
    *Subscription may be required

    Abstract

    By managing the authority assigned to each application, rule-based application-oriented access controls can significantly mitigate the threats posed by malicious code due to software vulnerabilities or malware. However, these policies are typically complex and difficult to develop. Learning modes can ease specification; however, they still require high levels of expertise to utilise correctly, and are most suited to confining nonmalicious software.

    This paper presents a novel approach to automating policy specification for rule-based application-oriented access controls. The functionality-based application confinement (FBAC) model provides reusable parameterised abstractions. A number of straightforward yet effective techniques are presented that use these functionality-based abstractions to create application policies a priori; that is, without running programs before policies are specified. These techniques automate the specification of policy details by analysing program dependencies, program management information, and filesystem contents.

    Publication Type: Conference Paper
    Murdoch Affiliation: School of Information Technology
    Publisher: IEEE
    Copyright: 2011 IEEE
    Conference Website: http://www.ares-conference.eu/conf/
    Notes: Appears In: Availability, Reliability and Security (ARES), 2011 Sixth International Conference on...Proceedings
    URI: http://researchrepository.murdoch.edu.au/id/eprint/4372
    Item Control Page

    Downloads

    Downloads per month over past year