Quacky: Quantitative Access Control Permissiveness Analyzer✱
Abstract
quacky is a tool for quantifying permissiveness of access control policies in the cloud. Given a policy, quacky translates it into a SMT formula and uses a model counting constraint solver to quantify permissiveness. When given multiple policies, quacky not only determines which policy is more permissive, but also quantifies the relative permissiveness between the policies. With quacky, policy authors can automatically analyze complex policies, helping them ensure that there is no unintended access to private data. quacky supports access control policies written in the Amazon Web Services (AWS) Identity and Access Management (IAM), Microsoft Azure, and Google Cloud Platform (GCP) policy languages. It has command-line and web interfaces. It is open-source and available at https://github.com/vlab-cs-ucsb/quacky.
BibTeX
@inproceedings{Eiers-al:ASE22,
author = {William Eiers and
Ganesh Sankaran and
Albert Li and
Emily O'Mahony and
Benjamin Prince and
Tevfik Bultan},
title = {Quacky: Quantitative Access Control Permissiveness Analyzer✱},
booktitle = {ASE},
pages = {163:1--163:5},
publisher = {{ACM}},
year = {2022},
}