|
ABSTRACT
Despite several research studies, the effective analysis of policy based systems remains a significant challenge. Policy analysis should at least (i) be expressive (ii) take account of obligations and authorizations, (iii) include a dynamic system model, and (iv) give useful diagnostic information. We present a logic-based policy analysis framework which satisfies these requirements, showing how many significant policy-related properties can be analysed, and we give details of a prototype implementation.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
Dalal Alrajeh , Oliver Ray , Alessandra Russo , Sebastian Uchitel, Extracting Requirements from Scenarios with ILP, Inductive Logic Programming: 16th International Conference, ILP 2006, Santiago de Compostela, Spain, August 24-27, 2006, Revised Selected Papers, Springer-Verlag, Berlin, Heidelberg, 2007
[doi> 10.1007/978-3-540-73847-3_14]
|
| |
2
|
A. Bandara, S. Calo, R. Craven, J. Lobo, E. Lupu, J. Ma, A. Russo, and M. Sloman. An expressive policy analysis framework with enhanced system dynamicity. Technical Report, Department of Computing, Imperial College London, 2008.
|
| |
3
|
A. K. Bandara, E. C. Lupu, A. Russo, N. Dulay, M. Sloman, P. Flegkas, M. Charalambides, and G. Pavlou. Policy refinement for diffserv quality of service management. In Integrated Network Management, pages 469--482. IEEE, 2005.
|
| |
4
|
S. Barker. Security policy specification in logic. In Proc. of Int. Conf. on AI, pages 143--148, June 2000.
|
| |
5
|
M. Y. Becker and S. Nanz. A logic for state-modifying authorization policies. In ESORICS, pages 203--218, 2007.
|
| |
6
|
M. Y. Becker and S. Nanz. The role of abduction in declarative authorization policies. In P. Hudak and D. S. Warren, editors, PADL, volume 4902 of LNCS, pages 84--99. Springer, 2008.
|
| |
7
|
|
| |
8
|
D. F. C. Brewer and M. J. Nash. The chinese wall security policy. In IEEE Symposium on S & P, pages 206--214, 1989.
|
 |
9
|
Glenn Bruns , Daniel S Dantas , Michael Huth, A simple and expressive semantic framework for policy composition in access control, Proceedings of the 2007 ACM workshop on Formal methods in security engineering, p.12-21, November 02-02, 2007, Fairfax, Virginia, USA
[doi> 10.1145/1314436.1314439]
|
| |
10
|
|
| |
11
|
S. Chen, D. Wijesekera, and S. Jajodia. Incorporating dynamic constraints in the flexible authorization framework. In ESORICS, pages 1--16, 2004.
|
 |
12
|
|
| |
13
|
|
| |
14
|
D. J. Dougherty, K. Fisler, and S. Krishnamurthi. Specifying and reasoning about dynamic access-control policies. In U. Furbach and N. Shankar, editors, IJCAR, volume 4130 of LNCS, pages 632--646. Springer, 2006.
|
| |
15
|
D. J. Dougherty, K. Fisler, and S. Krishnamurthi. Obligations and their interaction with programs. In ESORICS, pages 375--389, 2007.
|
| |
16
|
D. Ferraiolo and D. Kuhn. Role based access control. In 15th National Computer Security Conference, pages 554--563, 1992.
|
 |
17
|
Kathi Fisler , Shriram Krishnamurthi , Leo A. Meyerovich , Michael Carl Tschantz, Verification and change-impact analysis of access-control policies, Proceedings of the 27th international conference on Software engineering, May 15-21, 2005, St. Louis, MO, USA
[doi> 10.1145/1062455.1062502]
|
| |
18
|
M. Gelfond and V. Lifschitz. The stable model semantics for logic programming. In R. Kowalski and K. Bowen, editors, Proc. 5th International Conference and Symposium on Logic Programming, pages 1070--1080, Seattle, Washington, August 15--19 1988.
|
| |
19
|
|
 |
20
|
|
 |
21
|
|
 |
22
|
|
| |
23
|
|
 |
24
|
Sushil Jajodia , Pierangela Samarati , V. S. Subrahmanian , Eliza Bertino, A unified framework for enforcing multiple access control policies, Proceedings of the 1997 ACM SIGMOD international conference on Management of data, p.474-485, May 11-15, 1997, Tucson, Arizona, United States
|
| |
25
|
|
| |
26
|
|
| |
27
|
J. McCarthy. Elaboration tolerance. In Proc. Common Sense 98, 1998.
|
| |
28
|
|
| |
29
|
|
| |
30
|
OASIS XACML TC. extensible access control markup language (XACML) v2.0, 2005.
|
| |
31
|
|
 |
32
|
|
| |
33
|
|
| |
34
|
B. Van Nuffelen. Abductive constraint logic programming: implementation and applications. PhD thesis, K. U. Leuven, Belgium, June 2004.
|
|