Logo image
Attribute Based Access Control for APIs in Spring Security
Conference proceeding

Attribute Based Access Control for APIs in Spring Security

Alessandro Armando, Roberto Carbone, Eyasu Getahun Chekole, Silvio Ranise and ACM
SACMAT '14 : proceedings of the 19th ACM Symposium on Access Control Models and Technologies : June 25-27, 2014, London, Ontario, Canada, pp.85-88
01/01/2014

Abstract

Computer Science Computer Science, Theory & Methods Science & Technology Technology
The widespread adoption of Application Programming Interfaces (APIs) by enterprises is changing the way business is done by permitting the implementation of a multitude of apps, customized to user needs. While supporting a more flexible exploitation of available data, services and applications developed on top of APIs are vulnerable to a variety of attacks, ranging from SQL injection to unauthorized access of sensitive data. Available security solutions must be re-used and/or adapted to work with APIs. In this paper, we focus on the development of a flexible access control mechanism for APIs. This is an important security mechanism to guarantee the enforcement of authorization constraints on resources while invoking their API functions. We have developed an extension of the Spring Security framework, the standard for securing services and apps built in the popular (open source) Spring framework, for the specification and enforcement of Attribute-Based Access Control (ABAC) policies. We demonstrate our work with scenarios arising in a smart energy eco-system.

Metrics

1 Record Views

Details

Logo image