Open Research Newcastle
Browse

A practical task-based approach to access control configurations

Download (1.93 MB)
report
posted on 2025-05-09, 08:11 authored by Rukshan I. Athauda, Euijoon Ahn
Configuring optimal access control is a difficult task in today's complex IT environments. Too restrictive access control leads to frustration by users, while excessive privileges leads to vulnerabilities. Unfortunately, the problem of verifying safety - i.e. no rights can be leaked to an unauthorised principal - for an arbitrary configuration of a general access model is shown to be undecidable. In this paper, a practical methodology and framework is proposed to elicit access control rights stealthily while users perform tasks in a test environment that mimic a real-production environment. To illustrate the feasibility of the framework, a prototype is implemented and presented.

History

Publisher

No Publisher available.

Language

  • en, English

College/Research Centre

Faculty of Science and Information Technology

School

School of Design, Communication and Information Technology

Usage metrics

    Reports

    Categories

    No categories selected

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC