OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: web application access control research

From: George W. Capehart (gwccapehassoc.com)
Date: Tue Apr 22 2003 - 20:21:25 CDT


On Tuesday 22 April 2003 06:46 pm, absmithcerias.purdue.edu wrote:
> All,
>
> Besides the OWASP Guide, can anyone point me to papers/articles that
> deal with the issues of access control of web applications?
>
> I am looking to do a survey paper on this topic. Basically, I am
> looking for references that talk about access control in regards to
> web applications: current trends, research, tools, software, ideas,
> etc.

Hello Andy,

A good source for the use of RBAC with Web applications can be found at
http://csrc.nist.gov/rbac under the heading "RBAC for Web Servers."
Lots of goodies (even source) there . . .

Regards,
--
George W. Capehart

"With sufficient thrust, pigs fly just fine . . ."
 -- RFC 1925