Title
The functionality-based application confinement model
Abstract
This paper presents the functionality-based application confinement (FBAC) access control model. FBAC is an application-oriented access control model, intended to restrict processes to the behaviour that is authorised by end users, administrators, and processes, in order to limit the damage that can be caused by malicious code, due to software vulnerabilities or malware. FBAC is unique in its ability to limit applications to finely grained access control rules based on high-level easy-to-understand reusable policy abstractions, its ability to simultaneously enforce application-oriented security goals of administrators, programs, and end users, its ability to perform dynamic activation and deactivation of logically grouped portions of a process's authority, its approach to process invocation history and intersection-based privilege propagation, its suitability to policy automation techniques, and in the resulting usability benefits. Central to the model are `functionalities', hierarchical and parameterised policy abstractions, which can represent features that applications provide; `confinements', which can model simultaneous enforcement of multiple sets of policies to enforce a diverse range of types of application restrictions; and `applications', which represent the processes to be confined. The paper defines the model in terms of structure (which is described in five components) and function, and serves as a culmination of our work thus far, reviewing the evaluation of the model that has been conducted to date.
Year
DOI
Venue
2013
10.1007/s10207-013-0199-4
International Journal of Information Security
Keywords
Field
DocType
application-oriented access control,policy abstraction,sandboxing,usable security
Sandbox (computer security),End user,Computer security,Computer science,Usability,Automation,Software,Access control,Malware,restrict
Journal
Volume
Issue
ISSN
12
5
1615-5270
Citations 
PageRank 
References 
0
0.34
24
Authors
3
Name
Order
Citations
PageRank
Z. Cliffe Schreuders1304.67
Christian Payne2334.71
Tanya McGill3294.94