conference-paper

Detecting Covert Channels in Cloud Access Control Policies Using Large Language Models

Research footprint

At a glance

Citations
0
References
8
Comments
0
Paper overview

Abstract

In the realm of cloud computing, the task of configuring access control policies is a critical aspect of ensuring security of cloud resources. However, policy configuration remains a complex task with a high cognitive load as it requires a simultaneous understanding of the cloud environment and security requirements of the organization. This often creates gaps between intended and actual policy configuration leading to misconfigurations of policies. A misconfigured policy can introduce subtle and unexpected vulnerabilities that can be exploited by malicious entities to gain unauthorized access to cloud resources. In this paper, we model and analyze a particular class of access control vulnerabilities that arise due to the creation of covert channels in role-based access control policies. We present a tool CovertHunter that uses a Large Language Model to recognize intent behind policy configuration described in natural language and check it against actual cloud policies to automatically detect vulnerabilities arising due to the presence of covert channels.

Record transparency

Publication details

DOI
10.1109/csr61664.2024.10679435
OpenAlex
W4402811979
Document type
conference-paper
Language
EN
Last metadata update
Community

Comments

Log in to join the discussion.

  1. No comments yet. Start the discussion.