Invalidating policies using structural information

Kammueller, Florian ORCID logoORCID: https://orcid.org/0000-0001-5839-5488 and Probst, Christian (2013) Invalidating policies using structural information. In: IEEE CS Security and Privacy Workshops, SPW, WRIT'13. . [Conference or Workshop Item]

Abstract

Insider threats are a major threat to many organisations. Even worse, insider attacks are usually hard to detect, especially if an attack is based on actions that the attacker has the right to perform. In this paper we present a step towards detecting the risk for this kind of attacks by invalidating policies using structural information of the organisational model. Based on this structural information and a description of the organisation's policies, our approach invalidates the policies and identifies exemplary sequences of actions that lead to a violation of the policy in question. Based on these examples, the organisation can identify real attack vectors that might result in an insider attack. This information can be used to refine access control system or policies.

Item Type: Conference or Workshop Item (Paper)
Research Areas: A. > School of Science and Technology > Computer Science
Item ID: 15208
Depositing User: Florian Kammueller
Date Deposited: 23 Apr 2015 11:49
Last Modified: 13 Oct 2016 14:33
URI: https://eprints.mdx.ac.uk/id/eprint/15208

Actions (login required)

View Item View Item

Statistics

Activity Overview
6 month trend
0Downloads
6 month trend
415Hits

Additional statistics are available via IRStats2.