conference-paper
Open access
ProfessorX: Detecting Silent Vulnerabilities in Policy Engine Implementations
Research footprint
At a glance
- Citations
- 0
- References
- 27
- Comments
- 0
Paper overview
Öz
Enterprises that own or handle sensitive resources rely on access control models to protect those resources. NIST has recently standardized a new access control model called Next Generation Access Control (NGAC) and provided a reference implementation. Despite the importance of properly functioning access control systems, little work has been done to verify that the software implementing NGAC properly conforms to the NGAC standard. Prior approaches for finding bugs are either designed to detect fail-stop faults, or model the protocol or software itself, which does not identify discrepancies between software and standards.
Record transparency
Publication details
- DOI
- 10.1145/3734436.3734446
- OpenAlex
- W4411995701
- Document type
- conference-paper
- Language
- EN
- Last metadata update
Comments
Oturum Açın to join the discussion.