Copyright © 1995 Published by Elsevier Science Ltd.
Refereed paper
Redundant access rights
Available online 16 December 1999.
References and further reading may be available for this article. To view references and further reading you must purchase this article.
Abstract
In this paper we predict the existence of many unused (or ‘redundant’) access rights in access control systems and consider the implications that this has for security. We present a way of measuring the number of redundant access rights in a contemporary access control system, and provide measurements taken from real computer systems to support our theories. These results help to explain the apparently poor reliability of access control as a security enforcing function, and open new possibilities for improving security based upon heuristics for determining and eliminating redundant access rights.
Author Keywords: Security; Access control; Redundancy; Protection; Privacy






E-mail Article
Add to my Quick Links

Cited By in Scopus (2)




