With the growing prevalence of cloud computing, providing secure access to information stored in the cloud has become a critical problem. Due to the complexity of access control policies, administrators may inadvertently allow unintended access to private information, and this is a common source of data breaches in cloud based services. In this paper, we present a quantitative symbolic analysis approach for automated policy repair in order to fix overly permissive policies. We encode the semantics of the access control policies using SMT formulas and assess their permissiveness using model counting. Given a policy, a permissiveness bound, and a set of requests that should be allowed, we iteratively repair the policy through permissiveness reduction and refinement, so that the permissiveness bound is reached while the given set of requests are still allowed. We demonstrate the effectiveness of our automated policy repair technique by applying it to policies written in Amazon's AWS Identity and Access Management (IAM) policy language.

Tue 18 Jul

Displayed time zone: Pacific Time (US & Canada) change

10:30 - 12:00
ISSTA 1: Program Repair and DebuggingTechnical Papers at Amazon Auditorium (Gates G20)
Chair(s): Andreas Zeller CISPA Helmholtz Center for Information Security
10:30
15m
Talk
Improving Spectrum-Based Localization of Multiple Faults by Iterative Test Suite Reduction
Technical Papers
Dylan Callaghan Stellenbosch University, Bernd Fischer Stellenbosch University
DOI
10:45
15m
Talk
A Bayesian Framework for Automated Debugging
Technical Papers
Sungmin Kang KAIST, Wonkeun Choi KAIST, Shin Yoo KAIST
DOI Pre-print
11:00
15m
Talk
ConfFix: Repairing Configuration Compatibility Issues in Android Apps
Technical Papers
Huaxun Huang Hong Kong University of Science and Technology, Chi Xu The Hong Kong University of Science and Technology, Ming Wen Huazhong University of Science and Technology, Yepang Liu Southern University of Science and Technology, Shing-Chi Cheung Hong Kong University of Science and Technology
DOI
11:15
15m
Talk
Quantitative Policy Repair for Access Control on the Cloud
Technical Papers
William Eiers University of California at Santa Barbara, Ganesh Sankaran University of California at Santa Barbara, Tevfik Bultan University of California at Santa Barbara
DOI
11:30
15m
Talk
Automated Program Repair from Fuzzing Perspective
Technical Papers
YoungJae Kim Ulsan National Institute of Science and Technology, Seungheon Han Ulsan National Institute of Science and Technology, Askar Yeltayuly Khamit Ulsan National Institute of Science and Technology, Jooyong Yi UNIST (Ulsan National Institute of Science and Technology)
DOI