%0 Journal Article
%T Analysis on Implicit Authorization in Privilege Through Rule Deduction
基于规则推导的特权隐式授权分析
%A CAI Jia-Yong
%A QING Si-Han
%A LIU Wei
%A HE Jian-Bo
%A
蔡嘉勇
%A 卿斯汉
%A 刘伟
%A 何建波
%J 软件学报
%D 2008
%I
%X A scheme on studying the safety issues for privilege in systems is introduced.Since the particular faculty of transiting security states makes analyzing and protecting privilege for a system difficult,techniques used in traditional access control should not copy to this field.For this reason the features are firstly inspected by discussing the origination of privilege using access control space theory.Then rules defined for a system could be divided into two categories:constraint rules and execution rules,describing the restrictions and effect of an authorization respectively.Furthermore,a special authorization relation between different privilege operations,as well as its properties,is investigated against rules' logical patterns by deduction.A quick algorithm for constructing authorization deduction graph is also provided.Basing on it,common safety issue of implicit authorization was reviewed with the possibility to be abused.Finally this paper formalizes the capability mechanism defined by POSIX (portable operating system interface) standard,constructing ADG (authorization deduction graph) for it.The design is revised with countermeasures against privilege abusing so as to preserve consistent with the principle of least privilege.
%K privilege
%K constraint rule
%K execution rule
%K deduction
%K implicit authorization
特权
%K 约束规则
%K 执行规则
%K 推导
%K 隐式授权
%U http://www.alljournals.cn/get_abstract_url.aspx?pcid=5B3AB970F71A803DEACDC0559115BFCF0A068CD97DD29835&cid=8240383F08CE46C8B05036380D75B607&jid=7735F413D429542E610B3D6AC0D5EC59&aid=47747F874E5409AEAF3A00F9244353CE&yid=67289AFF6305E306&vid=2A8D03AD8076A2E3&iid=5D311CA918CA9A03&sid=3852E53ACC3276FE&eid=C875244499E644B2&journal_id=1000-9825&journal_name=软件学报&referenced_num=0&reference_num=12