Communication publiée dans un périodique (Colloques, congrès, conférences scientifiques et actes)
Refactoring Access Control Policies for Performance Improvement
ELKATEB, Donia; MOUELHI, Tejeddine; LE TRAON, Yves et al.
2012In Proceedings of the 3rd ACM/SPEC International Conference on Performance Engineering (ICPE 2012), p. 100-110
Peer reviewed
 

Documents


Texte intégral
Refactoring Access Control Policies.pdf
Postprint Éditeur (962.89 kB)
Télécharger

Tous les documents dans ORBilu sont protégés par une licence d'utilisation.

Envoyer vers



Détails



Mots-clés :
Access control; EXtensible access control markup language; Performance; Policy decision point; Policy enforcement point; Refactoring
Résumé :
[en] In order to facilitate managing authorization, access control architectures are designed to separate the business logic from an access control policy. To determine whether a user can access which resources, a request is formulated from a component, called a Policy Enforcement Point (PEP) located in application code. Given a request, a Policy Decision Point (PDP) evaluates the request against an access control policy and returns its access decision (i.e., permit or deny) to the PEP. With the growth of sensitive information for protection in an application, an access control policy consists of a larger number of rules, which often cause a performance bottleneck. To address this issue, we propose to refactor access control policies for performance improvement by splitting a policy (handled by a single PDP) into its corresponding multiple policies with a smaller number of rules (handled by multiple PDPs). We define seven attribute-set-based splitting criteria to facilitate splitting a policy. We have conducted an evaluation on three subjects of reallife Java systems, each of which interacts with access control policies. Our evaluation results show that (1) our approach preserves the initial architectural model in terms of interaction between the business logic and its corresponding rules in a policy, and (2) our approach enables to substantially reduce request evaluation time for most splitting criteria. Copyright 2012 ACM.
Disciplines :
Sciences informatiques
Identifiants :
UNILU:UL-CONFERENCE-2012-123
Auteur, co-auteur :
ELKATEB, Donia ;  University of Luxembourg > Faculty of Science, Technology and Communication (FSTC) > Computer Science and Communications Research Unit (CSC) ; University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
MOUELHI, Tejeddine ;  North Carolina State University, USA
LE TRAON, Yves ;  University of Luxembourg > Faculty of Science, Technology and Communication (FSTC) > Computer Science and Communications Research Unit (CSC)
Hwang, Jeehyun
Xie, Tao
Co-auteurs externes :
yes
Langue du document :
Anglais
Titre :
Refactoring Access Control Policies for Performance Improvement
Date de publication/diffusion :
2012
Nom de la manifestation :
the 3rd ACM/SPEC International Conference on Performance Engineering (ICPE 2012)
Lieu de la manifestation :
Boston, Etats-Unis - Massachusetts
Date de la manifestation :
21-25 April 2012
Manifestation à portée :
International
Titre du périodique :
Proceedings of the 3rd ACM/SPEC International Conference on Performance Engineering (ICPE 2012)
Pagination :
100-110
Peer reviewed :
Peer reviewed
Disponible sur ORBilu :
depuis le 03 avril 2016

Statistiques


Nombre de vues
192 (dont 0 Unilu)
Nombre de téléchargements
320 (dont 0 Unilu)

Bibliographie


Publications similaires



Contacter ORBilu