.

From model-driven specification to design-level set-based analysis of XACML policies

LAUR Repository

Show simple item record

dc.creator Mourad, Azzam en_US
dc.creator Tout, Hanine en_US
dc.creator Talhi, Chamseddine en_US
dc.creator Otrok, Hadi en_US
dc.creator Yahyaoui, Hamdi en_US
dc.date.accessioned 2017-02-06T07:41:09Z
dc.date.available 2017-02-06T07:41:09Z
dc.date.datecopyrighted 2016 en_US
dc.identifier.issn 0045-7906 en_US
dc.identifier.uri http://hdl.handle.net/10725/5181
dc.description.abstract With lot of hype surrounding policy-based computing, XACML (eXtensible Access Control Markup Language) has become the widely used de facto standard for managing access to open and distributed service-based environments like Web services. However, like any other policy language, XACML has complex syntax, which makes the policies specification process both time consuming and error prone, especially with large size policies that govern complex systems. Moreover, with the diversity of rules and conditions, hidden conflicts, redundancies and access flaws are more likely to arise, which expose Web services to security breaches at runtime. This paper proposes a UML profile that allows systematic model-driven specification of XACML policies to resolve the complexity of policies designation. Based on mathematical sets that explore the rules meanings, the paper provides also a design-level analysis to detect anomalies in the specified policies, prior to their enforcement in the system. A real life case study demonstrates the feasibility and efficiency of the proposition. en_US
dc.language.iso en en_US
dc.title From model-driven specification to design-level set-based analysis of XACML policies en_US
dc.type Article en_US
dc.description.version Published en_US
dc.creator.school SAS en_US
dc.creator.identifier 2009004853 en_US
dc.creator.department Computer Science and Mathematics en_US
dc.description.embargo N/A en_US
dc.relation.ispartof Computers & Electrical Engineering en_US
dc.description.volume 52 en_US
dc.article.pages 65-79 en_US
dc.keywords Web services security en_US
dc.keywords XACML policies en_US
dc.keywords Model-driven specification en_US
dc.keywords Design-level analysis en_US
dc.keywords Logical deductions en_US
dc.keywords Access control en_US
dc.identifier.doi http://dx.doi.org/10.1016/j.compeleceng.2015.09.021 en_US
dc.identifier.ctation Mourad, A., Tout, H., Talhi, C., Otrok, H., & Yahyaoui, H. (2016). From model-driven specification to design-level set-based analysis of XACML policies. Computers & Electrical Engineering, 52, 65-79. en_US
dc.creator.email azzam.mourad@lau.edu.lb en_US
dc.description.tou http://libraries.lau.edu.lb/research/laur/terms-of-use/articles.php en_US
dc.identifier.url http://www.sciencedirect.com/science/article/pii/S0045790615003420 en_US
dc.identifier.orcid https://orcid.org/0000-0001-9434-5322
dc.identifier.orcid https://orcid.org/0000-0001-9434-5322 en_US
dc.creator.ispartof Lebanese American University en_US


Files in this item

This item appears in the following Collection(s)

Show simple item record

Search LAUR


Advanced Search

Browse

My Account