Block public access: trust safety verification of access control policies
Abstract
Data stored in cloud services is highly sensitive and so access to it is controlled via policies written in domain-specific languages (DSLs). The expressiveness of these DSLs provides users flexibility to cover a wide variety of uses cases, however, unintended misconfigurations can lead to potential security issues. We introduce Block Public Access, a tool that formally verifies policies to ensure that they only allow access to trusted principals, i.e. that they prohibit access to the general public. To this end, we formalize the notion of Trust Safety that formally characterizes whether or not a policy allows unconstrained (public) access. Next, we present a method to compile the policy down to a logical formula whose unsatisfiability can be (1) checked by SMT and (2) ensures Trust Safety. The constructs of the policy DSLs render unsatisfiability checking PSPACE-complete, which precludes verifying the millions of requests per second seen at cloud scale. Hence, we present an approach that leverages the structure of the policy DSL to compute a much smaller residual policy that corresponds only to untrusted accesses. Our approach allows Block Public Access to, in the common case, syntactically verify Trust Safety without having to query the SMT solver. We have implemented Block Public Access and present an evaluation showing how the above optimization yields a low-latency policy verifier that the S3 team at AWS has integrated into their authorization system, where it is currently in production, analyzing millions of policies everyday to ensure that client buckets do not grant unintended public access.
BibTeX
@inproceedings{Bouchet-al:FSE20,
author = {Malik Bouchet and
Byron Cook and
Bryant Cutler and
Anna Druzkina and
Andrew Gacek and
Liana Hadarean and
Ranjit Jhala and
Brad Marshall and
Daniel Peebles and
Neha Rungta and
Cole Schlesinger and
Chriss Stephens and
Carsten Varming and
Andy Warfield},
title = {Block public access: trust safety verification of access control policies},
booktitle = {{ESEC/SIGSOFT} {FSE}},
pages = {281--291},
publisher = {{ACM}},
year = {2020},
}