作者: Azzam Mourad , Hanine Tout , Chamseddine Talhi , Hadi Otrok , Hamdi Yahyaoui
DOI: 10.1016/J.COMPELECENG.2015.09.021
关键词: Computer security 、 Markup language 、 Access control 、 Syntax (programming languages) 、 XACML 、 Computer science 、 Process (engineering) 、 De facto standard 、 Policy analysis 、 Web service
摘要: We provide UML profile for model-driven specification of XACML policies.We propose a set-based design-level policy analysis approach.We devise algorithms detection conflicts, redundancies, and flaws.We dynamic policies evaluation to control access critical resources. Display Omitted With lot hype surrounding policy-based computing, (eXtensible Access Control Markup Language) has become the widely used de facto standard managing open distributed service-based environments like Web services. However, any other language, complex syntax, which makes process both time consuming error prone, especially with large size that govern systems. Moreover, diversity rules conditions, hidden redundancies flaws are more likely arise, expose services security breaches at runtime. This paper proposes allows systematic resolve complexity designation. Based on mathematical sets explore meanings, provides also detect anomalies in specified policies, prior their enforcement system. A real life case study demonstrates feasibility efficiency proposition.