Entry Marinovic:2014:RIB from tissec.bib
Last update: Sun Oct 15 02:58:48 MDT 2017
Top |
Symbols |
Numbers |
Math |
A |
B |
C |
D |
E |
F |
G |
H |
I |
J |
K |
L |
M |
N |
O |
P |
Q |
R |
S |
T |
U |
V |
W |
X |
Y |
Z
BibTeX entry
@Article{Marinovic:2014:RIB,
author = "Srdjan Marinovic and Naranker Dulay and Morris
Sloman",
title = "{Rumpole}: an Introspective Break-Glass Access Control
Language",
journal = j-TISSEC,
volume = "17",
number = "1",
pages = "2:1--2:??",
month = aug,
year = "2014",
CODEN = "ATISBQ",
DOI = "https://doi.org/10.1145/2629502",
ISSN = "1094-9224 (print), 1557-7406 (electronic)",
ISSN-L = "1094-9224",
bibdate = "Mon Aug 11 19:17:17 MDT 2014",
bibsource = "http://portal.acm.org/;
http://www.math.utah.edu/pub/tex/bib/tissec.bib",
abstract = "Access control policies define what resources can be
accessed by which subjects and under which conditions.
It is, however, often not possible to anticipate all
subjects that should be permitted access and the
conditions under which they should be permitted. For
example, predicting and correctly encoding all
emergency and exceptional situations is impractical.
Traditional access control models simply deny all
requests that are not permitted, and in doing so may
cause unpredictable and unacceptable consequences. To
overcome this issue, break-glass access control models
permit a subject to override an access control denial
if he accepts a set of obligatory actions and certain
override conditions are met. Existing break-glass
models are limited in how the override decision is
specified. They either grant overrides for a predefined
set of exceptional situations, or they grant unlimited
overrides to selected subjects, and as such, they
suffer from the difficulty of correctly encoding and
predicting all override situations and permissions. To
address this, we develop Rumpole, a novel break-glass
language that explicitly represents and infers
knowledge gaps and knowledge conflicts about the
subject's attributes and the contextual conditions,
such as emergencies. For example, a Rumpole policy can
distinguish whether or not it is known that an
emergency holds. This leads to a more informed decision
for an override request, whereas current break-glass
languages simply assume that there is no emergency if
the evidence for it is missing. To formally define
Rumpole, we construct a novel many-valued logic
programming language called Beagle. It has a simple
syntax similar to that of Datalog, and its semantics is
an extension of Fitting's bilattice-based semantics for
logic programs. Beagle is a knowledge non-monotonic
language, and as such, is strictly more expressive than
current many-valued logic programming languages.",
acknowledgement = ack-nhfb,
articleno = "2",
fjournal = "ACM Transactions on Information and System Security",
journal-URL = "http://portal.acm.org/browse_dl.cfm?idx=J789",
}
Related entries
- accessed,
13(3)28
- action,
2(2)177,
11(1)3,
11(4)21,
12(1)1,
12(2)12,
12(3)19,
13(4)30,
14(1)10,
14(4)28,
16(1)3,
17(4)13
- address,
2(1)65,
2(4)390,
10(2)8,
10(3)12,
11(1)4,
11(2)3,
11(3)12,
12(2)11,
13(3)22,
13(3)26,
13(4)31,
13(4)38,
13(4)40,
14(1)3,
15(1)2,
15(2)6,
15(2)8,
16(3)11,
16(4)14,
17(1)1,
17(1)4,
17(2)8,
17(3)11
- all,
1(1)93,
2(2)159,
2(3)332,
2(4)416,
10(1)4,
10(2)5,
10(4)2,
10(4)4,
11(2)1,
11(2)3,
11(2)4,
11(2)5,
11(2)6,
11(3)13,
11(4)18,
11(4)20,
11(4)22,
12(2)10,
12(3)18,
13(1)10,
13(3)25,
13(3)28,
13(4)38,
13(4)41,
14(1)6,
14(1)14,
14(3)27,
15(1)4,
15(2)9,
15(3)14,
15(4)16,
15(4)17,
16(1)4,
17(3)9,
17(3)11,
18(1)2,
18(2)5
- assume,
11(3)12,
11(3)15,
11(4)20,
15(3)12
- attributes,
2(3)269,
11(1)3,
12(2)8,
13(3)22,
13(4)31,
13(4)32,
15(1)4
- called,
1(1)3,
1(1)66,
2(1)105,
2(2)177,
2(3)269,
10(1)4,
11(1)3,
11(3)14,
12(3)15,
13(1)10,
13(3)26,
13(3)27,
14(1)13,
14(4)28,
15(1)2,
15(2)9,
15(4)18,
16(2)6,
17(3)10,
17(4)16,
18(1)3
- cause,
6(4)443,
12(2)10,
12(2)11,
12(2)12,
12(4)20,
14(1)2,
14(1)13,
18(4)14
- certain,
10(2)5,
11(2)1,
11(4)22,
12(1)1,
12(1)6,
12(2)8,
12(4)20,
13(3)26,
13(4)40,
15(2)9,
17(3)10,
18(2)7
- condition,
1(1)26,
2(3)295,
10(4)1,
11(1)3,
11(2)2,
11(4)21,
12(2)11,
13(3)26,
16(1)3,
18(1)2,
18(2)5,
18(2)6
- conflict,
2(1)3,
13(4)40,
14(1)9,
15(4)15,
16(4)17
- consequence,
2(2)138,
12(1)2,
14(1)2,
16(2)5,
16(4)14
- construct,
9(2)181,
12(1)3,
12(3)19,
13(4)36,
15(1)2,
17(2)7
- correctly,
11(4)22,
16(3)11
- current,
2(1)34,
2(1)65,
2(2)177,
2(4)390,
11(4)18,
11(4)20,
11(4)22,
12(2)8,
12(2)10,
13(3)20,
13(4)35,
15(3)12,
16(3)10,
16(4)13,
16(4)16,
17(1)1,
17(2)6,
17(3)9
- Datalog,
16(4)17
- decision,
1(1)3,
1(1)26,
10(4)2,
11(1)3,
14(1)3,
15(3)13,
16(1)3,
16(4)16,
18(1)3
- define,
1(1)26,
2(2)177,
10(1)3,
10(1)4,
10(2)8,
10(4)2,
10(4)5,
12(1)1,
12(3)19,
13(3)24,
13(3)27,
13(4)29,
13(4)36,
14(1)9,
14(1)14,
14(3)25,
16(1)4,
17(1)4
- denial,
12(2)12,
15(2)6
- deny,
14(1)9
- develop,
2(2)138,
10(2)8,
10(3)9,
11(3)12,
12(1)4,
12(1)6,
12(3)14,
13(3)22,
13(3)27,
14(1)9,
14(4)32,
15(1)3,
15(2)9,
15(2)10,
16(2)7,
16(3)10
- difficulty,
3(3)186,
10(4)3,
11(3)16
- distinguish,
1(1)66,
16(3)12,
18(3)9
- doing,
11(3)16,
14(1)2,
18(4)13
- either,
2(4)390,
10(1)2,
11(1)2,
11(2)3,
11(4)18,
11(4)23,
12(1)2,
13(4)33,
14(1)9,
15(3)14,
15(4)17,
16(4)15,
16(4)16,
16(4)17,
18(2)5
- emergency,
12(4)20
- encoding,
10(3)12
- evidence,
12(1)4,
12(2)9,
13(3)25,
17(3)12,
18(1)1,
18(4)14
- example,
10(4)5,
12(1)1,
12(2)11,
12(3)19,
12(4)20,
13(3)20,
13(4)30,
13(4)35,
13(4)39,
13(4)40,
15(2)10,
16(1)3,
16(2)5,
16(3)10,
17(1)4,
18(1)1,
18(2)8,
18(4)13
- exceptional,
13(4)41
- existing,
1(1)93,
11(1)2,
11(3)15,
11(4)22,
11(4)23,
12(1)1,
12(1)2,
12(1)3,
12(2)12,
12(3)14,
13(3)27,
13(4)36,
14(1)13,
14(3)25,
14(4)30,
15(1)4,
15(2)9,
15(3)12,
16(2)5,
16(3)10,
16(4)15,
17(1)4,
17(2)5,
17(2)7,
17(4)15,
18(1)1,
18(3)10
- explicitly,
13(1)10,
16(4)16
- expressive,
1(1)93,
11(4)21,
12(1)1,
13(3)20,
13(3)28,
14(1)8,
14(1)9,
15(3)13,
16(4)17
- extension,
1(1)93,
2(1)105,
10(1)2,
10(3)10,
11(1)4,
12(3)16,
12(3)18,
13(3)21,
16(1)4,
17(2)7
- formally,
1(1)26,
2(3)230,
9(4)421,
10(3)9,
10(4)2,
11(3)13,
11(4)17,
12(2)8,
13(3)24,
13(3)27,
14(4)30,
17(1)3
- gap,
14(4)31,
15(1)3,
15(3)13,
16(2)7
- grant,
14(1)9
- has,
1(1)93,
2(1)105,
2(2)138,
2(3)230,
2(3)269,
2(3)332,
9(4)391,
10(1)3,
10(1)4,
10(3)10,
11(1)2,
11(2)2,
11(3)14,
11(4)17,
11(4)19,
11(4)22,
11(4)23,
12(1)2,
12(2)9,
12(2)10,
12(3)15,
12(4)22,
13(3)20,
13(3)25,
13(3)26,
13(3)27,
13(3)28,
13(4)36,
14(1)3,
14(1)12,
14(1)14,
14(3)26,
14(4)28,
15(1)2,
15(2)6,
15(2)10,
15(3)12,
16(2)8,
16(4)14,
17(1)3,
17(3)9,
17(3)11,
17(4)14,
17(4)15,
17(4)16,
18(2)7,
18(3)11,
18(4)14
- hold,
10(4)1,
11(2)6,
15(1)5,
16(1)4
- how,
2(1)3,
2(2)138,
2(3)269,
7(2)319,
10(2)5,
10(2)8,
10(4)1,
10(4)2,
10(4)5,
11(3)13,
11(4)18,
12(1)2,
12(2)9,
12(2)12,
12(3)18,
12(3)19,
13(1)10,
13(2)13,
13(3)25,
13(4)31,
13(4)36,
14(1)2,
14(3)26,
15(1)5,
15(3)14,
15(4)15,
16(1)3,
16(2)5,
16(2)8,
17(1)1,
17(1)3,
17(4)15,
18(1)1,
18(1)3,
18(2)6,
18(3)9,
18(4)14
- however,
2(3)269,
10(2)5,
10(2)8,
11(2)6,
11(3)15,
11(4)18,
11(4)20,
11(4)22,
13(3)20,
13(3)22,
13(4)35,
13(4)38,
13(4)39,
14(1)14,
14(3)24,
14(4)28,
14(4)29,
15(2)10,
16(2)7,
16(3)11,
17(1)4,
17(3)12,
17(4)15,
18(1)1,
18(2)7,
18(4)13
- impractical,
13(3)26,
14(4)29
- infer,
12(1)4,
15(4)15,
18(1)1
- informed,
18(3)9
- issue,
1(1)66,
2(1)65,
2(4)354,
8(4)349,
10(1)1,
10(3)12,
11(1)2,
12(1)5,
12(2)7,
12(3)15,
12(4)22,
13(1)1,
13(2)11,
13(3)22,
13(3)26,
13(4)32,
15(1)1,
15(2)7,
16(2)7,
16(3)12,
17(1)1
- knowledge,
10(3)12,
11(2)2,
11(3)15,
12(1)3,
12(1)4,
12(2)11,
13(4)35,
15(3)14,
17(3)9,
18(4)12
- known,
10(3)11,
10(4)1,
10(4)3,
11(2)1,
11(2)3,
11(2)4,
11(4)20,
13(1)10,
13(3)27,
13(4)33,
14(1)7,
14(3)27,
17(2)7,
18(1)1
- language,
2(1)65,
9(4)391,
9(4)421,
10(1)3,
10(2)8,
11(1)2,
11(1)4,
11(4)21,
12(1)1,
12(2)12,
13(3)20,
13(3)24,
13(3)26,
13(3)28,
14(1)9,
15(1)2,
15(2)8,
16(1)3,
16(3)9,
16(4)17,
17(1)3
- lead,
1(1)3,
2(1)3,
10(4)4,
10(4)5,
11(4)17,
12(1)2,
13(3)20,
13(4)29,
18(3)10,
18(4)13
- limited,
10(4)3,
12(1)2,
12(3)18,
14(4)31,
17(3)9,
17(3)10,
18(2)7
- logic,
2(1)3,
2(1)65,
2(3)332,
6(1)128,
6(4)501,
11(4)21,
12(1)1,
13(3)20,
14(1)8,
14(1)9,
16(4)17,
17(2)5,
18(2)7
- may,
2(2)138,
2(2)177,
9(4)391,
10(3)12,
10(4)2,
11(2)2,
11(2)5,
11(3)12,
11(4)18,
11(4)21,
12(1)5,
12(2)8,
12(3)15,
12(3)16,
13(1)10,
13(3)22,
13(3)25,
13(4)35,
13(4)38,
13(4)40,
15(2)10,
16(1)4,
17(1)4,
18(1)1,
18(2)5
- missing,
10(1)2,
12(2)13,
16(2)5
- more,
2(1)3,
2(1)65,
2(3)332,
9(2)181,
9(4)391,
9(4)421,
9(4)461,
10(1)4,
10(3)9,
10(4)1,
10(4)4,
10(4)6,
11(2)3,
11(2)4,
11(2)6,
11(3)14,
11(4)21,
12(1)1,
12(2)8,
12(2)10,
12(2)12,
12(2)13,
12(3)18,
13(1)10,
13(3)20,
13(3)21,
13(3)22,
13(3)28,
13(4)32,
13(4)34,
13(4)39,
14(3)27,
14(4)31,
15(1)2,
15(1)5,
15(2)8,
15(2)9,
15(3)11,
15(3)12,
15(4)16,
16(1)2,
16(2)8,
16(3)10,
16(3)11,
16(4)17,
17(1)3,
17(3)9,
17(4)14,
17(4)16,
18(1)1,
18(3)11,
18(4)13
- not,
1(1)26,
2(1)65,
2(2)177,
2(3)230,
2(3)269,
2(4)390,
9(4)421,
10(1)3,
10(4)2,
11(1)3,
11(1)4,
11(2)2,
11(2)4,
11(2)5,
11(3)12,
11(3)13,
11(3)15,
11(3)16,
11(4)19,
11(4)20,
11(4)22,
12(1)1,
12(1)2,
12(1)3,
12(1)6,
12(2)10,
12(2)11,
12(2)13,
12(3)14,
12(4)22,
13(1)10,
13(3)28,
13(4)33,
13(4)35,
13(4)36,
13(4)37,
13(4)39,
13(4)40,
14(3)23,
14(3)27,
14(4)28,
14(4)29,
14(4)31,
15(2)6,
15(2)9,
15(2)10,
15(3)12,
15(3)13,
16(1)1,
16(2)5,
16(2)6,
16(3)9,
16(3)12,
16(4)13,
16(4)15,
16(4)16,
17(3)10,
17(4)15,
18(1)1,
18(3)9,
18(4)13
- novel,
2(3)269,
9(4)461,
10(1)4,
10(3)12,
11(1)2,
11(1)3,
11(2)2,
11(4)18,
11(4)19,
12(1)4,
12(3)16,
14(1)5,
15(1)4,
16(1)1,
16(4)16,
17(3)9,
17(4)14,
18(1)4,
18(4)12
- often,
2(1)65,
10(1)4,
10(2)8,
10(3)10,
10(3)12,
11(1)2,
11(3)12,
11(4)20,
16(2)5,
17(1)4
- overcome,
14(4)31,
16(1)3
- permission,
1(1)26,
2(1)105,
10(1)2,
10(2)5,
10(4)2,
12(4)20,
13(3)24,
13(3)27,
15(4)15
- permit,
12(1)3
- permitted,
1(1)26,
11(4)21,
12(1)1,
16(1)4
- possible,
2(1)105,
10(2)5,
10(4)2,
10(4)4,
11(2)6,
11(3)16,
11(4)22,
12(1)6,
12(2)10,
13(3)28,
13(4)33,
13(4)35,
13(4)39,
14(1)3,
14(1)14,
14(3)25,
14(4)32,
15(2)10,
17(3)9,
18(1)4,
18(3)9
- predefined,
11(2)6
- program,
2(1)65,
2(3)332,
11(3)14,
12(1)1,
12(2)10,
12(2)11,
12(3)16,
12(3)19,
13(3)21,
14(3)24,
15(1)2,
15(2)10,
16(2)7,
17(3)11,
18(1)4
- programming,
6(4)501,
10(2)7,
12(1)6,
15(1)2,
15(2)8
- represent,
11(4)21,
14(1)3,
15(4)15
- request,
1(1)66,
10(1)3,
11(2)3,
13(3)20,
14(1)2,
14(1)8,
14(1)9,
16(4)13,
16(4)14,
16(4)17
- resource,
2(3)332,
9(4)391,
10(4)4,
11(1)2,
11(1)3,
11(1)4,
11(2)2,
11(3)14,
11(4)19,
11(4)20,
12(1)1,
12(1)6,
12(4)22,
13(3)20,
14(1)7,
14(1)10,
15(4)18,
17(3)9,
18(2)6
- selected,
2(3)295,
17(1)1,
18(1)1
- semantic,
1(1)93,
10(2)8,
10(4)2,
11(4)21,
12(2)13,
12(3)14,
13(2)12,
13(3)21,
13(4)36,
14(3)25,
15(3)13,
16(1)1,
16(2)7,
17(1)3,
17(2)7
- set,
2(1)34,
2(2)138,
2(4)390,
8(1)3,
9(4)421,
10(2)5,
10(3)12,
10(4)2,
10(4)3,
10(4)5,
11(2)1,
11(2)3,
11(3)13,
11(4)18,
11(4)21,
12(2)11,
12(3)18,
12(3)19,
12(4)20,
12(4)21,
13(1)9,
13(1)10,
13(3)27,
13(4)40,
14(1)12,
14(3)25,
14(4)31,
15(1)2,
15(2)7,
15(2)10,
15(3)13,
15(4)15,
16(1)4,
17(2)8,
17(3)11,
17(4)13,
17(4)14,
18(1)4,
18(3)10,
18(3)11
- should,
1(1)3,
10(3)9,
10(4)2,
12(2)8,
12(4)20,
13(3)28,
13(4)35,
17(3)11,
18(4)14
- similar,
9(4)391,
10(4)1,
11(4)18,
13(1)10,
16(1)1,
17(1)1
- simple,
2(3)230,
5(3)203,
9(2)181,
10(1)4,
10(3)11,
12(2)9,
12(2)13,
12(3)18,
12(4)21,
12(4)22,
13(3)26,
13(4)33,
14(3)27,
15(2)9,
15(4)17,
18(1)1
- simply,
16(4)15,
17(3)9,
17(3)11
- situation,
2(3)230,
10(4)4,
11(3)12,
12(4)20,
15(2)10
- specified,
1(1)26,
9(4)421,
10(4)2,
11(1)3,
11(1)4,
11(2)4,
12(3)19,
13(3)20,
13(3)28,
13(4)35
- subject,
1(1)26,
9(2)162,
9(4)421,
11(1)3,
11(1)4,
11(3)12,
13(3)26,
14(1)7,
15(3)12,
17(4)14,
18(2)5
- suffer,
10(4)4,
15(1)4,
16(2)7,
18(4)12
- syntax,
11(4)21,
16(2)5
- than,
2(1)3,
2(1)65,
2(3)332,
9(4)391,
9(4)461,
10(1)4,
11(2)3,
11(2)6,
11(3)14,
12(1)1,
12(2)10,
12(3)16,
12(4)22,
13(1)10,
13(3)21,
13(4)29,
13(4)31,
13(4)35,
14(3)27,
14(4)31,
15(1)5,
15(2)9,
15(2)10,
15(4)15,
15(4)16,
16(2)8,
16(4)17,
17(3)9,
17(3)10,
17(3)12,
17(4)14,
17(4)16,
18(4)13
- there,
11(2)6,
12(1)2,
12(2)8,
12(4)20,
13(3)21,
13(4)34,
14(1)9,
14(4)30,
14(4)31,
15(4)18,
16(1)4
- traditional,
1(1)93,
2(3)269,
10(4)4,
11(4)22,
12(1)3,
12(2)10,
12(4)21,
14(1)3,
15(1)2,
16(2)8,
17(3)12,
17(4)14,
17(4)16,
18(2)7
- unlimited,
17(3)9
- unpredictable,
18(2)7
- what,
2(2)138,
10(4)1,
12(2)9,
15(2)10,
17(3)11
- whereas,
12(3)18,
18(4)14
- whether,
1(1)3,
1(1)26,
10(2)5,
10(4)2,
10(4)5,
11(2)3,
11(2)6,
11(3)16,
12(1)1,
12(4)20,
13(3)26,
13(4)40,
14(3)25,
14(4)32,
16(1)3,
16(1)4,
17(1)1