Title
Protecting users from "themselves"
Abstract
Computer usage and threat models have changed drastically since the advent of access control systems in the 1960s. Instead of multiple users sharing a single file system, each user has many devices with their own storage. Thus, a user's fear has shifted away from other users' impact on the same system to the threat of malice in the software they intentionally or even inadvertently run. As a result, we propose a new vision for access control: one where individual users are isolated by default and where the access of individual user applications is carefully managed. A key question is how much user administration effort would be required if a system implementing this vision were constructed. In this paper, we outline our work on just such a system, called PinUP, which manages file access on a per application basis for each user. We use historical data from our lab's users to explore how much user and system administration effort is required. Since administration is required for user sharing in PinUP, we find that sharing via mail and file repositories requires a modest amount of administrative effort, a system policy change every couple of days and a small number of user administrative operations a day. We are encouraged that practical administration on such a scale is possible given an appropriate and secure user approach.
Year
DOI
Venue
2007
10.1145/1314466.1314472
CSAW
Keywords
Field
DocType
secure user approach,multiple user,protecting user,system administration effort,access control system,individual user application,user sharing,single file system,individual user,user administrative operation,user administration effort,access control
File system,World Wide Web,Computer science,Threat model,Computer security,Software,Computer usage,User modeling,Access control,Malice,System administration
Conference
Citations 
PageRank 
References 
2
0.38
8
Authors
7
Name
Order
Citations
PageRank
William Enck12832221.77
Sandra Rueda213712.72
Joshua Schiffman328421.79
Yogesh Sreenivasan4332.53
Luke St. Clair5836.80
T Jaeger62635255.67
P. McDaniel77174494.57