摘要
为了解决Web分布式系统中的隐私安全策略在制定和变更中的错误很难被发现的问题,提出了策略变更中各种情况的相应变更影响分析算法。对以可扩展访问控制标记语言(XACML)为代表的隐私安全策略语言中的变更理论进行了研究,定义了变更分析中的相关概念,通过把策略中的字符串元素转化成对应整数值建立一个优化的树形数据结构,利用树的特征分析变更后果。这使得一个管理员可以在正式应用策略变更前检验即将实施的变更是否符合自己的真正意图,从而大大增强系统安全性。最后实现了一个原型系统,并可以应用到其他标准策略语言。
Due to the lack of tools for analyzing policies, most authorization policies on the Internet have been plagued with policy errors. A policy error either creates security vulnerabilities that will compromise the security of information technology system. A major source of policy errors stems from policy changes. Authorization policies often need to be changed as networks evolve and new requests emerge. The theory and algorithms for authorization policy change-impact analysis were presented. Algorithms in this paper took an authorization policy and a proposed change as input, and then output the accurate impact of the change. Thus, an administrator can verify a proposed change before committing it. A prototype was built to demonstrate the use of the algorithms.
出处
《计算机应用》
CSCD
北大核心
2011年第1期115-117,共3页
journal of Computer Applications
基金
国家863计划项目(2009AA01Z4222)
关键词
可扩展访问控制标记语言
隐私安全策略
变更影响分析
树形结构
eXtcnsible Access Control Markup Language (XACML)
authorization policy
change impact analysis
tree structure