Analysis of role reachability with transitive tags

Methods, systems, and computer-readable media for analysis of role reachability with transitive tags are disclosed. An access control analyzer determines a graph including nodes and edges. The nodes represent roles in a provider network hosting resources. The roles are associated with access control...

Full description

Saved in:
Bibliographic Details
Main Authors Kroening, Daniel, Cook, John Byron, Naser Pastoriza, Alejandro, Peebles, Daniel George, Rungta, Neha, Varming, Carsten
Format Patent
LanguageEnglish
Published 09.07.2024
Subjects
Online AccessGet full text

Cover

Loading…
More Information
Summary:Methods, systems, and computer-readable media for analysis of role reachability with transitive tags are disclosed. An access control analyzer determines a graph including nodes and edges. The nodes represent roles in a provider network hosting resources. The roles are associated with access control policies granting or denying access to individual resources. One or more of the access control policies grant or deny access based (at least in part) on key-value attributes. The access control analyzer determines, based (at least in part) on a role reachability analysis of the graph, whether a first role can assume a second role using role assumption steps for a particular state of the attributes. The attributes may include transitive attributes that persist during the role assumption steps.
Bibliography:Application Number: US202017119855