@inproceedings{fb6cb2aecffc472aa29e2c25a9640b04,
title = "Automatically Tightening Access Control Policies with Restricter",
abstract = "Robust access control is a cornerstone of secure software, systems, and networks. An access control mechanism is as effective as the policy it enforces. However, authoring effective policies that satisfy desired properties such as the principle of least privilege is a challenging task even for experienced administrators. In this paper, we set out to address this pain point by proposing Restricter, which automatically tightens each (permit) policy rule of a policy with respect to an access log, which captures some already exercised access requests and their corresponding access decisions (i.e., allow or deny). Restricter achieves policy tightening by reducing the number of access requests permitted by a policy rule without sacrificing the functionality of the underlying system it is regulating. We implement Restricter for Amazon{\textquoteright}s Cedar policy language and demonstrate its effectiveness through two realistic case studies.",
keywords = "Access Control, Security Policy, SyGuS",
author = "Wu, \{Ka Lok\} and Christa Jenkins and Stoller, \{Scott D.\} and Omar Chowdhury",
note = "Publisher Copyright: {\textcopyright} The Author(s) 2026.; 32nd International Conference on Tools and Algorithms for the Construction and Analysis of Systems, TACAS 2026, Held as Part of the International Joint Conferences on Theory and Practice of Software, ETAPS 2026 ; Conference date: 11-04-2026 Through 16-04-2026",
year = "2026",
doi = "10.1007/978-3-032-22752-2\_6",
language = "English",
isbn = "9783032227515",
series = "Lecture Notes in Computer Science",
publisher = "Springer Science and Business Media Deutschland GmbH",
pages = "110--129",
editor = "Sebastian Junges and Guy Katz",
booktitle = "Tools and Algorithms for the Construction and Analysis of Systems - 32nd International Conference, TACAS 2026, Held as Part of the International Joint Conferences on Theory and Practice of Software, ETAPS 2026, Proceedings",
}