Publication | Closed Access
Semantic-based Automated Reasoning for AWS Access Policies using SMT
89
Citations
12
References
2018
Year
Unknown Venue
Provisioning (Technology)EngineeringInformation SecurityVerificationSemantic WebSoftware AnalysisFormal VerificationCloud Resource ManagementLogical Access ControlAccess ControlSystems EngineeringData IntegrationData ManagementSemantic-based Automated ReasoningAmazon Web ServicesRuntime VerificationPolicy LanguageData PrivacyCloud Computing SecurityComputer ScienceData SecurityAutomated ReasoningData AccessCloud ComputingFormal MethodsPolicy Properties
Cloud computing provides on-demand access to IT resources via the Internet. Permissions for these resources are defined by expressive access control policies. This paper presents a formalization of the Amazon Web Services (AWS) policy language and a corresponding analysis tool, called ZELKOVA, for verifying policy properties. ZELKOVA encodes the semantics of policies into SMT, compares behaviors, and verifies properties. It provides users a sound mechanism to detect misconfigurations of their policies. ZELKOVA solves a PSPACE-complete problem and is invoked many millions of times daily.
| Year | Citations | |
|---|---|---|
Page 1
Page 1