Lecture 3 - ABAC Flashcards

1
Q

ABAC?

A

ABAC controls access based on attributes of the users, the
resources to be accessed, and current environmental conditions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is a concern with ABAC?

A

performance, as resource and user properties would have to be evaluated on each access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is ABAC exceptionally good for and why?

A

web services, as these already have a high performance cost on each access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What does ABAC stand for?

A

Attribute Based Access Control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Is the subject a passive or active entity?

A

active

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Is the object a passive or active entity?

A

passive

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is special about environment attributes?

A

They’re usually ignored in most access control policies that are implemented

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How many independent sources of information are used to make the access control decision?

A

4 these are attrbutes for 3 entities and the access control policy (rules)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Advantages of ABAC?

A

powerful and extremely flexible

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Disadvantages of ABAC?

A

complex to implement and design
performance can be poor

hence there is a tradeoff on complexity and performance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is a policy?

A

The set of rules and relationships that govern allowable behaviour within a system.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are privileges?

A

represent authorized behaviour of a subject

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How is a policy written?

A

From the perspective of the privilages available to subjects (what they can do) and how the object needs protecting.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Example rule?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly