Emily O'Mahony

dblp:322/7686 · DBLP profile ↗
← Back
2ranked-venue papers
0as first author
2since 2021 · last 2022
0000-0003-0894-9774ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 2 · 2 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
2 papers
Authentication and access control · 100%
Computer architecture, parallel and distributed computing, and storage systems
1 paper
Cloud and datacenter computing · 100%

Topics — the 3 heaviest of 4, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Authentication and access control › access control policy engineering
access control verification
1.122022
Quacky: Quantitative Access Control Permissiveness Analyzer✱ · ASE 2022
Quantifying Permissiveness of Access Control Policies · ICSE 2022
Authentication and access control › access control
policy verification
0.212022
Quantifying Permissiveness of Access Control Policies · ICSE 2022
Cloud and datacenter computing › cloud security
cloud access control
0.212022
Quacky: Quantitative Access Control Permissiveness Analyzer✱ · ASE 2022

Methods — techniques the papers use, named apart from their topics

model counting · 1.7SMT · 1.1constraint solving · 0.6
YearPublicationVenuePosition
2022 Quantifying Permissiveness of Access Control Policies
abstract
Due to ubiquitous use of software services, protecting the confidentiality of private information stored in compute clouds is becoming an increasingly critical problem. Although access control specification languages and libraries provide mechanisms for protecting confidentiality of information, without verification and validation techniques that can assist developers in writing policies, complex policy specifications are likely to have errors that can lead to unintended and unauthorized access to data, possibly with disastrous consequences. In this paper, we present a quantitative and differential policy analysis framework that not only identifies if one policy is more permissive than another policy, but also quantifies the relative permissiveness of access control policies. We quantify permissiveness of policies using a model counting constraint solver. We present a heuristic that transforms constraints extracted from access control policies and significantly improves the model counting performance. We demonstrate the effectiveness of our approach by applying it to policies written in Amazon's AWS Identity and Access Management (IAM) policy language and Microsoft's Azure policy language.
William Eiers, Ganesh Sankaran, Albert Li, Emily O'Mahony, Benjamin Prince, Tevfik Bultan
ICSE4
2022 Quacky: Quantitative Access Control Permissiveness Analyzer✱
abstract
quacky is a tool for quantifying permissiveness of access control policies in the cloud. Given a policy, quacky translates it into a SMT formula and uses a model counting constraint solver to quantify permissiveness. When given multiple policies, quacky not only determines which policy is more permissive, but also quantifies the relative permissiveness between the policies. With quacky, policy authors can automatically analyze complex policies, helping them ensure that there is no unintended access to private data. quacky supports access control policies written in the Amazon Web Services (AWS) Identity and Access Management (IAM), Microsoft Azure, and Google Cloud Platform (GCP) policy languages. It has command-line and web interfaces. It is open-source and available at https://github.com/vlab-cs-ucsb/quacky.
William Eiers, Ganesh Sankaran, Albert Li, Emily O'Mahony, Benjamin Prince, Tevfik Bultan
ASE4