What is it about?
Administrative policies are used to control the operations that access control administrators can perform. They are typically used to ensure that administrators actions do not cause a security risk. This paper presents a visual language, using graphs, to define administrative policies. Since it uses a generic access control model, the results are applicable to a variety of access control models and languages.
Featured Image
Photo by Max Langelott on Unsplash
Why is it important?
Policy administration is difficult due to the complexity of the systems that need to be protected and the risks associated with policy update errors. For this reason, administrative operations need to be carefully controlled. In this paper we show that administrative operations are naturally specified by graph rewriting rules, making it easier to visualise policy changes. We classify administrative actions in two groups: a group of generic actions that are available in all policies, and a second group of application-specific actions. We prove that the generic actions preserve validity of the policy, and characterise classes of rules that preserve policy properties. We also discuss policy-analysis techniques to help administrators check that policies satisfy the required constraints. Our framework is flexible, it is easy to extend it to define new, domain-specific policies when needed, simply by specialising the set of actions and adding rules.
Read the Original
This page is a summary of: Graph-Based Specification of Admin-CBAC Policies, April 2021, ACM (Association for Computing Machinery),
DOI: 10.1145/3422337.3447850.
You can read the full text:
Contributors
The following have contributed to this page







