In communication networks with policy-based Transport Control on-Demand (TCoD) function,the transport control policies play a great impact on the network effectiveness. To evaluate and optimize the transport policies ...In communication networks with policy-based Transport Control on-Demand (TCoD) function,the transport control policies play a great impact on the network effectiveness. To evaluate and optimize the transport policies in communication network,a policy-based TCoD network model is given and a comprehensive evaluation index system of the network effectiveness is put forward from both network application and handling mechanism perspectives. A TCoD network prototype system based on Asynchronous Transfer Mode/Multi-Protocol Label Switching (ATM/MPLS) is introduced and some experiments are performed on it. The prototype system is evaluated and analyzed with the comprehensive evaluation index system. The results show that the index system can be used to judge whether the communication network can meet the application requirements or not,and can provide references for the optimization of the transport policies so as to improve the communication network effectiveness.展开更多
A main challenge of attribute-based access control(ABAC)is the handling of missing information.Several studies have shown that the way standard ABAC mechanisms,e.g.based on XACML,handle missing information is flawed,m...A main challenge of attribute-based access control(ABAC)is the handling of missing information.Several studies have shown that the way standard ABAC mechanisms,e.g.based on XACML,handle missing information is flawed,making ABAC policies vulnerable to attribute-hiding attacks.Recent work has addressed the problem of missing information in ABAC by introducing the notion of extended evaluation,where the evaluation of a query considers all queries that can be obtained by extending the initial query.This method counters attribute-hiding attacks,but a na飗e implementation is intractable,as it requires an evaluation of the whole query space.In this paper,we present a framework for the extended evaluation of ABAC policies.The framework relies on Binary Decision Diagram(BDDs)data structures for the efficient computation of the extended evaluation of ABAC policies.We also introduce the notion of query constraints and attribute value power to avoid evaluating queries that do not represent a valid state of the system and to identify which attribute values should be considered in the computation of the extended evaluation,respectively.We illustrate our framework using three real-world policies,which would be intractable with the original method but which are analyzed in seconds using our framework.展开更多
A main challenge of attribute-based access control(ABAC)is the handling of missing information.Several studies have shown that the way standard ABAC mechanisms,e.g.based on XACML,handle missing information is flawed,m...A main challenge of attribute-based access control(ABAC)is the handling of missing information.Several studies have shown that the way standard ABAC mechanisms,e.g.based on XACML,handle missing information is flawed,making ABAC policies vulnerable to attribute-hiding attacks.Recent work has addressed the problem of missing information in ABAC by introducing the notion of extended evaluation,where the evaluation of a query considers all queries that can be obtained by extending the initial query.This method counters attribute-hiding attacks,but a naïve implementation is intractable,as it requires an evaluation of the whole query space.In this paper,we present a framework for the extended evaluation of ABAC policies.The framework relies on Binary Decision Diagram(BDDs)data structures for the efficient computation of the extended evaluation of ABAC policies.We also introduce the notion of query constraints and attribute value power to avoid evaluating queries that do not represent a valid state of the system and to identify which attribute values should be considered in the computation of the extended evaluation,respectively.We illustrate our framework using three real-world policies,which would be intractable with the original method but which are analyzed in seconds using our framework.展开更多
给出一种采用多层次优化技术的XACML(extensible access control markup language)策略评估引擎实现方案MLOBEE(multi-level optimization based evaluation engine).策略判定评估前,对原始策略库实施规则精化,缩减策略规模并调整规则顺...给出一种采用多层次优化技术的XACML(extensible access control markup language)策略评估引擎实现方案MLOBEE(multi-level optimization based evaluation engine).策略判定评估前,对原始策略库实施规则精化,缩减策略规模并调整规则顺序;判定评估过程中,在引擎内部采用多种缓存机制,分别建立判定结果缓存、属性缓存和策略缓存,有效降低判定引擎和其他功能部件的通信损耗.通过两阶段索引实现的策略缓存,可显著降低匹配运算量并提高策略匹配准确率.仿真实验验证了MLOBEE所采用的多层次优化技术的有效性,其整体评估性能明显优于大多数同类系统.展开更多
基金Supported by the National 863 Program (No.2007AA-701210)
文摘In communication networks with policy-based Transport Control on-Demand (TCoD) function,the transport control policies play a great impact on the network effectiveness. To evaluate and optimize the transport policies in communication network,a policy-based TCoD network model is given and a comprehensive evaluation index system of the network effectiveness is put forward from both network application and handling mechanism perspectives. A TCoD network prototype system based on Asynchronous Transfer Mode/Multi-Protocol Label Switching (ATM/MPLS) is introduced and some experiments are performed on it. The prototype system is evaluated and analyzed with the comprehensive evaluation index system. The results show that the index system can be used to judge whether the communication network can meet the application requirements or not,and can provide references for the optimization of the transport policies so as to improve the communication network effectiveness.
基金This work is partially funded by the ITEA3 project APPSTACLE(15017)the ECSEL project SECREDAS(783119).
文摘A main challenge of attribute-based access control(ABAC)is the handling of missing information.Several studies have shown that the way standard ABAC mechanisms,e.g.based on XACML,handle missing information is flawed,making ABAC policies vulnerable to attribute-hiding attacks.Recent work has addressed the problem of missing information in ABAC by introducing the notion of extended evaluation,where the evaluation of a query considers all queries that can be obtained by extending the initial query.This method counters attribute-hiding attacks,but a na飗e implementation is intractable,as it requires an evaluation of the whole query space.In this paper,we present a framework for the extended evaluation of ABAC policies.The framework relies on Binary Decision Diagram(BDDs)data structures for the efficient computation of the extended evaluation of ABAC policies.We also introduce the notion of query constraints and attribute value power to avoid evaluating queries that do not represent a valid state of the system and to identify which attribute values should be considered in the computation of the extended evaluation,respectively.We illustrate our framework using three real-world policies,which would be intractable with the original method but which are analyzed in seconds using our framework.
基金partially funded by the ITEA3 project APPSTACLE(15017)the ECSEL project SECREDAS(783119).
文摘A main challenge of attribute-based access control(ABAC)is the handling of missing information.Several studies have shown that the way standard ABAC mechanisms,e.g.based on XACML,handle missing information is flawed,making ABAC policies vulnerable to attribute-hiding attacks.Recent work has addressed the problem of missing information in ABAC by introducing the notion of extended evaluation,where the evaluation of a query considers all queries that can be obtained by extending the initial query.This method counters attribute-hiding attacks,but a naïve implementation is intractable,as it requires an evaluation of the whole query space.In this paper,we present a framework for the extended evaluation of ABAC policies.The framework relies on Binary Decision Diagram(BDDs)data structures for the efficient computation of the extended evaluation of ABAC policies.We also introduce the notion of query constraints and attribute value power to avoid evaluating queries that do not represent a valid state of the system and to identify which attribute values should be considered in the computation of the extended evaluation,respectively.We illustrate our framework using three real-world policies,which would be intractable with the original method but which are analyzed in seconds using our framework.
文摘给出一种采用多层次优化技术的XACML(extensible access control markup language)策略评估引擎实现方案MLOBEE(multi-level optimization based evaluation engine).策略判定评估前,对原始策略库实施规则精化,缩减策略规模并调整规则顺序;判定评估过程中,在引擎内部采用多种缓存机制,分别建立判定结果缓存、属性缓存和策略缓存,有效降低判定引擎和其他功能部件的通信损耗.通过两阶段索引实现的策略缓存,可显著降低匹配运算量并提高策略匹配准确率.仿真实验验证了MLOBEE所采用的多层次优化技术的有效性,其整体评估性能明显优于大多数同类系统.