首页    期刊浏览 2024年07月08日 星期一
登录注册

文章基本信息

  • 标题:Invalidating Policies using Structural Information
  • 本地全文:下载
  • 作者:Florian Kammüller ; Christian W. Probst
  • 期刊名称:Journal of Wireless Mobile Networks, Ubiquitous Computing, and Dependable Applications
  • 印刷版ISSN:2093-5374
  • 电子版ISSN:2093-5382
  • 出版年度:2014
  • 卷号:5
  • 期号:2
  • 页码:59-79
  • 出版社:Innovative Information Science & Technology Research Group
  • 摘要:Insider threats are a major threat to many organisations. Even worse, insider attacks are usually hard to detect, especially if an attack is based on actions that the attacker has the right to perform. In this paper we present a step towards detecting the risk for this kind of attacks by invalidating policies using structural information of the organisational model. Based on this structural information and a description of the organisation's policies, our approach invalidates the policies and identifies exem- plary sequences of actions that lead to a violation of the policy in question. Based on these examples, the organisation can identify real attack vectors that might result in an insider attack. This informa- tion can be used to refine access control systems or policies. We provide case studies showing how mechanical verification tools, i.e. modelchecking with MCMAS and interactive theorem proving in Isabelle/HOL, can be applied to support the invalidation and thereby the identification of the attack vectors.
  • 关键词:organisational structure; policies; formal methods
国家哲学社会科学文献中心版权所有