Automatically Tightening Access Control Policies with Restricter

📅 2026-01-21
📈 Citations: 0
Influential: 0
📄 PDF

career value

187K/year
🤖 AI Summary
This work addresses the prevalent issue of over-privileged access control policies that violate the principle of least privilege, often leading to security misconfigurations. To mitigate this, the authors propose a novel method that automatically refines policy rules by analyzing historical access logs and rewriting permission rules in the Amazon Cedar policy language. The approach ensures that system functionality remains unchanged while significantly tightening granted permissions. This study presents the first automated realization of the least privilege principle in practice, demonstrating its effectiveness in two real-world scenarios: it substantially reduces the scope of permitted access, thereby enhancing security, without disrupting normal system operations.

Technology Category

Application Category

📝 Abstract
Robust access control is a cornerstone of secure software, systems, and networks. An access control mechanism is as effective as the policy it enforces. However, authoring effective policies that satisfy desired properties such as the principle of least privilege is a challenging task even for experienced administrators, as evidenced by many real instances of policy misconfiguration. In this paper, we set out to address this pain point by proposing Restricter, which automatically tightens each (permit) policy rule of a policy with respect to an access log, which captures some already exercised access requests and their corresponding access decisions (i.e., allow or deny). Restricter achieves policy tightening by reducing the number of access requests permitted by a policy rule without sacrificing the functionality of the underlying system it is regulating. We implement Restricter for Amazon's Cedar policy language and demonstrate its effectiveness through two realistic case studies.
Problem

Research questions and friction points this paper is trying to address.

access control policy
policy tightening
least privilege
policy misconfiguration
access log
Innovation

Methods, ideas, or system contributions that make the work stand out.

access control policy
policy tightening
least privilege
automated policy refinement
Cedar
K
Ka Lok Wu
Stony Brook University, Stony Brook NY 11794, USA
C
Christa Jenkins
Galois, Inc. Portland, OR 97204, USA
S
S. Stoller
Stony Brook University, Stony Brook NY 11794, USA
O
Omar Chowdhury
Stony Brook University, Stony Brook NY 11794, USA