{"id":"https://openalex.org/W2986159792","doi":"https://doi.org/10.1145/3319535.3363191","title":"Towards Continuous Access Control Validation and Forensics","display_name":"Towards Continuous Access Control Validation and Forensics","publication_year":2019,"publication_date":"2019-11-06","ids":{"openalex":"https://openalex.org/W2986159792","doi":"https://doi.org/10.1145/3319535.3363191","mag":"2986159792"},"language":"en","primary_location":{"id":"doi:10.1145/3319535.3363191","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3319535.3363191","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3319535.3363191","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3319535.3363191","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5076462299","display_name":"Chengcheng Xiang","orcid":"https://orcid.org/0000-0001-5230-8881"},"institutions":[{"id":"https://openalex.org/I36258959","display_name":"University of California, San Diego","ror":"https://ror.org/0168r3w48","country_code":"US","type":"education","lineage":["https://openalex.org/I36258959"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Chengcheng Xiang","raw_affiliation_strings":["University of California, San Diego, San Diego, CA, USA"],"affiliations":[{"raw_affiliation_string":"University of California, San Diego, San Diego, CA, USA","institution_ids":["https://openalex.org/I36258959"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5089383587","display_name":"Yudong Wu","orcid":null},"institutions":[{"id":"https://openalex.org/I36258959","display_name":"University of California, San Diego","ror":"https://ror.org/0168r3w48","country_code":"US","type":"education","lineage":["https://openalex.org/I36258959"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Yudong Wu","raw_affiliation_strings":["University of California, San Diego, San Diego, CA, USA"],"affiliations":[{"raw_affiliation_string":"University of California, San Diego, San Diego, CA, USA","institution_ids":["https://openalex.org/I36258959"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5032756714","display_name":"Bingyu Shen","orcid":"https://orcid.org/0000-0001-5518-3594"},"institutions":[{"id":"https://openalex.org/I36258959","display_name":"University of California, San Diego","ror":"https://ror.org/0168r3w48","country_code":"US","type":"education","lineage":["https://openalex.org/I36258959"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Bingyu Shen","raw_affiliation_strings":["University of California, San Diego, San Diego, CA, USA"],"affiliations":[{"raw_affiliation_string":"University of California, San Diego, San Diego, CA, USA","institution_ids":["https://openalex.org/I36258959"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5047417490","display_name":"Mingyao Shen","orcid":"https://orcid.org/0009-0006-2061-9013"},"institutions":[{"id":"https://openalex.org/I36258959","display_name":"University of California, San Diego","ror":"https://ror.org/0168r3w48","country_code":"US","type":"education","lineage":["https://openalex.org/I36258959"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Mingyao Shen","raw_affiliation_strings":["University of California, San Diego, San Diego, CA, USA"],"affiliations":[{"raw_affiliation_string":"University of California, San Diego, San Diego, CA, USA","institution_ids":["https://openalex.org/I36258959"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5079747680","display_name":"Hao\u2010Chen Huang","orcid":"https://orcid.org/0000-0001-6130-5981"},"institutions":[{"id":"https://openalex.org/I36258959","display_name":"University of California, San Diego","ror":"https://ror.org/0168r3w48","country_code":"US","type":"education","lineage":["https://openalex.org/I36258959"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Haochen Huang","raw_affiliation_strings":["University of California, San Diego, San Diego, CA, USA"],"affiliations":[{"raw_affiliation_string":"University of California, San Diego, San Diego, CA, USA","institution_ids":["https://openalex.org/I36258959"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5027605695","display_name":"Tianyin Xu","orcid":"https://orcid.org/0000-0003-4443-8170"},"institutions":[{"id":"https://openalex.org/I157725225","display_name":"University of Illinois Urbana-Champaign","ror":"https://ror.org/047426m28","country_code":"US","type":"education","lineage":["https://openalex.org/I157725225"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Tianyin Xu","raw_affiliation_strings":["University of Illinois Urbana-Champaign, Urbana, IL, USA"],"affiliations":[{"raw_affiliation_string":"University of Illinois Urbana-Champaign, Urbana, IL, USA","institution_ids":["https://openalex.org/I157725225"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5044337890","display_name":"Yuanyuan Zhou","orcid":"https://orcid.org/0000-0002-8703-219X"},"institutions":[{"id":"https://openalex.org/I36258959","display_name":"University of California, San Diego","ror":"https://ror.org/0168r3w48","country_code":"US","type":"education","lineage":["https://openalex.org/I36258959"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Yuanyuan Zhou","raw_affiliation_strings":["University of California, San Diego, San Diego, CA, USA"],"affiliations":[{"raw_affiliation_string":"University of California, San Diego, San Diego, CA, USA","institution_ids":["https://openalex.org/I36258959"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5089626823","display_name":"C. ULYSSES MOORE","orcid":"https://orcid.org/0000-0001-9531-3939"},"institutions":[{"id":"https://openalex.org/I36258959","display_name":"University of California, San Diego","ror":"https://ror.org/0168r3w48","country_code":"US","type":"education","lineage":["https://openalex.org/I36258959"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Cindy Moore","raw_affiliation_strings":["University of California, San Diego, San Diego, CA, USA"],"affiliations":[{"raw_affiliation_string":"University of California, San Diego, San Diego, CA, USA","institution_ids":["https://openalex.org/I36258959"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101520951","display_name":"Xinxin Jin","orcid":"https://orcid.org/0000-0003-4200-271X"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Xinxin Jin","raw_affiliation_strings":["Whova, Inc., San Diego, CA, USA"],"affiliations":[{"raw_affiliation_string":"Whova, Inc., San Diego, CA, USA","institution_ids":[]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5037875884","display_name":"Tianwei Sheng","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Tianwei Sheng","raw_affiliation_strings":["Whova, Inc., San Diego, CA, USA"],"affiliations":[{"raw_affiliation_string":"Whova, Inc., San Diego, CA, USA","institution_ids":[]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":10,"corresponding_author_ids":["https://openalex.org/A5076462299"],"corresponding_institution_ids":["https://openalex.org/I36258959"],"apc_list":null,"apc_paid":null,"fwci":3.3425,"has_fulltext":true,"cited_by_count":53,"citation_normalized_percentile":{"value":0.93094403,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":96,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"113","last_page":"129"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9993000030517578,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9993000030517578,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9988999962806702,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12127","display_name":"Software System Performance and Reliability","score":0.9954000115394592,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/access-control","display_name":"Access control","score":0.8618598580360413},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7412216663360596},{"id":"https://openalex.org/keywords/variety","display_name":"Variety (cybernetics)","score":0.5816386938095093},{"id":"https://openalex.org/keywords/control","display_name":"Control (management)","score":0.5556057095527649},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.5410711765289307},{"id":"https://openalex.org/keywords/physical-access","display_name":"Physical access","score":0.500565767288208},{"id":"https://openalex.org/keywords/security-policy","display_name":"Security policy","score":0.4778848886489868},{"id":"https://openalex.org/keywords/tree","display_name":"Tree (set theory)","score":0.44777345657348633},{"id":"https://openalex.org/keywords/role-based-access-control","display_name":"Role-based access control","score":0.4378892183303833},{"id":"https://openalex.org/keywords/unintended-consequences","display_name":"Unintended consequences","score":0.4357704520225525},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.16608622670173645}],"concepts":[{"id":"https://openalex.org/C527821871","wikidata":"https://www.wikidata.org/wiki/Q228502","display_name":"Access control","level":2,"score":0.8618598580360413},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7412216663360596},{"id":"https://openalex.org/C136197465","wikidata":"https://www.wikidata.org/wiki/Q1729295","display_name":"Variety (cybernetics)","level":2,"score":0.5816386938095093},{"id":"https://openalex.org/C2775924081","wikidata":"https://www.wikidata.org/wiki/Q55608371","display_name":"Control (management)","level":2,"score":0.5556057095527649},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5410711765289307},{"id":"https://openalex.org/C1304207","wikidata":"https://www.wikidata.org/wiki/Q7189582","display_name":"Physical access","level":3,"score":0.500565767288208},{"id":"https://openalex.org/C154908896","wikidata":"https://www.wikidata.org/wiki/Q2167404","display_name":"Security policy","level":2,"score":0.4778848886489868},{"id":"https://openalex.org/C113174947","wikidata":"https://www.wikidata.org/wiki/Q2859736","display_name":"Tree (set theory)","level":2,"score":0.44777345657348633},{"id":"https://openalex.org/C45567728","wikidata":"https://www.wikidata.org/wiki/Q1702839","display_name":"Role-based access control","level":3,"score":0.4378892183303833},{"id":"https://openalex.org/C2776889888","wikidata":"https://www.wikidata.org/wiki/Q1135789","display_name":"Unintended consequences","level":2,"score":0.4357704520225525},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.16608622670173645},{"id":"https://openalex.org/C199539241","wikidata":"https://www.wikidata.org/wiki/Q7748","display_name":"Law","level":1,"score":0.0},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.0},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0},{"id":"https://openalex.org/C134306372","wikidata":"https://www.wikidata.org/wiki/Q7754","display_name":"Mathematical analysis","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3319535.3363191","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3319535.3363191","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3319535.3363191","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.1145/3319535.3363191","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3319535.3363191","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3319535.3363191","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","score":0.46000000834465027,"display_name":"Peace, Justice and strong institutions"}],"awards":[{"id":"https://openalex.org/G1504002407","display_name":"CSR: Small: Practical methods for removing latent configuration errors in cloud platforms","funder_award_id":"1526966","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G2826744134","display_name":"SaTC: CORE: Small: Practical methods for detecting  access permission vulnerabilities caused by sysadmin's configuration errors","funder_award_id":"1814388","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G6806900785","display_name":null,"funder_award_id":"CNS-1814388, CNS-1526966","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"},{"id":"https://openalex.org/F4320331904","display_name":"Stony Brook University","ror":"https://ror.org/05qghxh33"},{"id":"https://openalex.org/F4320332603","display_name":"University of California, San Diego","ror":"https://ror.org/0168r3w48"}],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W2986159792.pdf","grobid_xml":"https://content.openalex.org/works/W2986159792.grobid-xml"},"referenced_works_count":57,"referenced_works":["https://openalex.org/W134722953","https://openalex.org/W433644524","https://openalex.org/W836115342","https://openalex.org/W1497174031","https://openalex.org/W1504694836","https://openalex.org/W1527417319","https://openalex.org/W1551045851","https://openalex.org/W1563423869","https://openalex.org/W1573585357","https://openalex.org/W1788765617","https://openalex.org/W1829128469","https://openalex.org/W1973948212","https://openalex.org/W1980644015","https://openalex.org/W1982022511","https://openalex.org/W1994411654","https://openalex.org/W1995301105","https://openalex.org/W2002011878","https://openalex.org/W2010657328","https://openalex.org/W2017872391","https://openalex.org/W2019514876","https://openalex.org/W2029039689","https://openalex.org/W2030696252","https://openalex.org/W2041783719","https://openalex.org/W2085952809","https://openalex.org/W2098972600","https://openalex.org/W2099419573","https://openalex.org/W2106525946","https://openalex.org/W2124776405","https://openalex.org/W2125055259","https://openalex.org/W2129308322","https://openalex.org/W2130136915","https://openalex.org/W2131889098","https://openalex.org/W2133441575","https://openalex.org/W2139974906","https://openalex.org/W2146356111","https://openalex.org/W2149706766","https://openalex.org/W2150847526","https://openalex.org/W2156299128","https://openalex.org/W2161899637","https://openalex.org/W2162308553","https://openalex.org/W2166559705","https://openalex.org/W2166602595","https://openalex.org/W2169046918","https://openalex.org/W2171295941","https://openalex.org/W2225112801","https://openalex.org/W2261611353","https://openalex.org/W2300491161","https://openalex.org/W2363172845","https://openalex.org/W2404990348","https://openalex.org/W2522470548","https://openalex.org/W2560674852","https://openalex.org/W2611573015","https://openalex.org/W2817857516","https://openalex.org/W3028407954","https://openalex.org/W3085162807","https://openalex.org/W4211218509","https://openalex.org/W4299689471"],"related_works":["https://openalex.org/W2105261429","https://openalex.org/W318167434","https://openalex.org/W1986933000","https://openalex.org/W2148952798","https://openalex.org/W2384733598","https://openalex.org/W819284483","https://openalex.org/W2387530238","https://openalex.org/W2382286253","https://openalex.org/W2054600748","https://openalex.org/W2362979444"],"abstract_inverted_index":{"Access":[0],"control":[1,31,53,91,100,119,141,178,219],"is":[2,41],"often":[3,43],"reported":[4],"to":[5,13,34,39,93,137,150,167],"be":[6,35],"\"profoundly":[7],"broken\"":[8],"in":[9,242],"real-world":[10,206],"practices":[11],"due":[12],"prevalent":[14],"policy":[15,101,128,142,220],"misconfigurations":[16],"introduced":[17],"by":[18,76],"system":[19],"administrators":[20],"(sysadmins).":[21],"Given":[22],"the":[23,125,152,161,169,176,186,234,239,245],"dynamics":[24],"of":[25,127,201,217,226,244],"resource":[26],"and":[27,103,116,164],"data":[28],"sharing,":[29],"access":[30,52,90,99,114,118,140,155,177,218,241],"policies":[32,120,163],"need":[33],"continuously":[36,112],"updated.":[37],"Unfortunately,":[38],"err":[40],"human-sysadmins":[42],"make":[44],"mistakes":[45,64],"such":[46,63],"as":[47],"over-granting":[48],"privileges":[49],"when":[50],"changing":[51],"policies.":[54],"With":[55],"today's":[56],"limited":[57],"tooling":[58],"support":[59],"for":[60,68,88,190],"continuous":[61],"validation,":[62],"can":[65,214,232],"stay":[66],"unnoticed":[67],"a":[69,85,132,146,191,199],"long":[70],"time":[71],"until":[72],"eventually":[73],"being":[74],"exploited":[75],"attackers,":[77],"causing":[78],"catastrophic":[79],"security":[80,109,193],"incidents.":[81],"We":[82,195],"present":[83],"P-DIFF,":[84],"practical":[86],"tool":[87],"monitoring":[89],"behavior":[92],"help":[94],"sysadmins":[95,159],"early":[96],"detect":[97,215],"unintended":[98],"changes":[102,166,179,188,221],"perform":[104],"postmortem":[105],"forensic":[106,229],"analysis":[107],"upon":[108],"attacks.":[110],"P-DIFF":[111,157,197,213,231],"monitors":[113],"logs":[115],"infers":[117],"from":[121,154,204,210],"them.":[122],"To":[123],"handle":[124],"challenge":[126],"evolution,":[129],"we":[130],"devise":[131],"novel":[133],"time-changing":[134],"decision":[135],"tree":[136,153],"effectively":[138],"represent":[139],"changes,":[143],"coupled":[144],"with":[145,160,198,222],"new":[147],"learning":[148],"algorithm":[149],"infer":[151],"logs.":[156],"provides":[158],"inferred":[162],"detected":[165],"assist":[168],"following":[170],"two":[171,209],"tasks:":[172],"(1)":[173],"validating":[174],"whether":[175],"are":[180],"intended":[181],"or":[182],"not;":[183],"(2)":[184],"pinpointing":[185],"historical":[187],"responsible":[189],"given":[192],"attack.":[194],"evaluate":[196],"variety":[200],"datasets":[202],"collected":[203],"five":[205],"systems,":[207],"including":[208],"industrial":[211],"companies.":[212],"86%-100%":[216],"an":[223],"average":[224],"precision":[225],"89%.":[227],"For":[228],"analysis,":[230],"pinpoint":[233],"root-cause":[235],"change":[236],"that":[237],"permits":[238],"target":[240],"85%-98%":[243],"evaluated":[246],"cases.":[247]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":11},{"year":2024,"cited_by_count":9},{"year":2023,"cited_by_count":14},{"year":2022,"cited_by_count":7},{"year":2021,"cited_by_count":8},{"year":2020,"cited_by_count":3}],"updated_date":"2026-04-10T15:06:20.359241","created_date":"2025-10-10T00:00:00"}
