TY - GEN
T1 - Dynamic mandatory access control for multiple stakeholders
AU - Rao, Vikhyath
AU - Jaeger, Trent
PY - 2009
Y1 - 2009
N2 - In this paper, we present a mandatory access control system that uses input from multiple stakeholders to compose policies based on runtime information. In the emerging open cell phone system environment, many devices run software whose access permissions depends on multiple stakeholders, such as the device owner, the service provider, the application owner, etc., rather than a single system administrator. However, current access control administration remains as either discretionary, allowing the running and perhaps compromised process to administer permissions, or mandatory, requiring a system administrator to know all permissions for all possible legal runs. A key problem is that users may download arbitrary programs to their devices, requiring that the system contain such programs while allowing some reasonable functionality. However, such programs may need access to permissions that in combination with other conflicting permissions may lead to an attack, such as allowing voice-over-IP calls. In our approach, we use a "soft" sand-boxing mechanism to first contain such processes, request the stakeholder to authorize operations outside the sandbox that are not prohibited by policy, and maintain a runtime execution role for the process to identify its access state to the stakeholders. We define a proxy policy server that caches and combines stakeholder policies to make such access decisions. Our framework was implemented by modifying the SELinux module and using a remote proxy policy server, although a local proxy policy server is also possible. We incur a 0.288 μs performance overhead only when stakeholders need to be consulted, and new permissions are cached.
AB - In this paper, we present a mandatory access control system that uses input from multiple stakeholders to compose policies based on runtime information. In the emerging open cell phone system environment, many devices run software whose access permissions depends on multiple stakeholders, such as the device owner, the service provider, the application owner, etc., rather than a single system administrator. However, current access control administration remains as either discretionary, allowing the running and perhaps compromised process to administer permissions, or mandatory, requiring a system administrator to know all permissions for all possible legal runs. A key problem is that users may download arbitrary programs to their devices, requiring that the system contain such programs while allowing some reasonable functionality. However, such programs may need access to permissions that in combination with other conflicting permissions may lead to an attack, such as allowing voice-over-IP calls. In our approach, we use a "soft" sand-boxing mechanism to first contain such processes, request the stakeholder to authorize operations outside the sandbox that are not prohibited by policy, and maintain a runtime execution role for the process to identify its access state to the stakeholders. We define a proxy policy server that caches and combines stakeholder policies to make such access decisions. Our framework was implemented by modifying the SELinux module and using a remote proxy policy server, although a local proxy policy server is also possible. We incur a 0.288 μs performance overhead only when stakeholders need to be consulted, and new permissions are cached.
UR - http://www.scopus.com/inward/record.url?scp=70450237083&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=70450237083&partnerID=8YFLogxK
U2 - 10.1145/1542207.1542217
DO - 10.1145/1542207.1542217
M3 - Conference contribution
AN - SCOPUS:70450237083
SN - 9781605585376
T3 - Proceedings of ACM Symposium on Access Control Models and Technologies, SACMAT
SP - 53
EP - 62
BT - SACMAT'09 - Proceedings of the 14th ACM Symposium on Access Control Models and Technologies
T2 - 14th ACM Symposium on Access Control Models and Technologies, SACMAT 2009
Y2 - 3 June 2009 through 5 June 2009
ER -