Sie befinden Sich nicht im Netzwerk der Universität Paderborn. Der Zugriff auf elektronische Ressourcen ist gegebenenfalls nur via VPN oder Shibboleth (DFN-AAI) möglich. mehr Informationen...
Elsevier Journal Backfiles on ScienceDirect (DFG Nationallizenzen)
Beschreibungen/Notizen
In this paper we predict the existence of many unused (or ‘redundant’) access rights in access control systems and consider the implications that this has for security. We present a way of measuring the number of redundant access rights in a contemporary access control system, and provide measurements taken from real computer systems to support our theories. These results help to explain the apparently poor reliability of access control as a security enforcing function, and open new possibilities for improving security based upon heuristics for determining and eliminating redundant access rights.