CASPR: Context-Aware Security Policy Recommendation

Lifang Xiao

Network and Distributed System Security (NDSS) Symposium 2025 · Day 3 · Software Security: Applications & Policies · Software Security: Applications & Policies

Overview

The talk "CASPR: Context-Aware Security Policy Recommendation" introduces an innovative approach to automate and enhance the configuration of security policies, specifically focusing on Security-Enhanced Linux (SE Linux). Presented by Ken from the University of Chinese Academy of Sciences on behalf of the original authors, the research addresses the pervasive challenge of manually managing complex access control policies. SE Linux, a mandatory access control system, relies on meticulously defined security policies to enforce the principle of least privilege, thereby preventing unauthorized access and bolstering system integrity. However, the sheer volume of policy rules and their intricate semantics make manual configuration a time-consuming, expertise-intensive, and error-prone endeavor.

Watch on YouTube · Slides

Key moments

  1. 0:00 Introduction to SE Nix and policy configuration challenges
  2. 2:00 CASPR's goal: context-aware policy recommendation for managing permissions
  3. 2:50 Methodology: using context-aware features with K-means clustering
  4. 4:40 Anomaly detection for policy integrity and completeness
  5. 6:00 Experimental setup and performance results on operating systems
  6. 6:50 Achieved 92.44% accuracy, outperforming other recommendation methods
  7. 8:00 Summary of contributions: context-aware information, CASPR method, experiments

CASPR: Context-Aware Security Policy Recommendation

Speakers: Lifang Xiao (Authors), Ken (Presenter), University of Chinese Academy of Sciences

Conference: NDSS Symposium

YouTube: https://www.youtube.com/watch?v=rknnoHURKkc

Overview

The talk "CASPR: Context-Aware Security Policy Recommendation" introduces an innovative approach to automate and enhance the configuration of security policies, specifically focusing on Security-Enhanced Linux (SE Linux). Presented by Ken from the University of Chinese Academy of Sciences on behalf of the original authors, the research addresses the pervasive challenge of manually managing complex access control policies. SE Linux, a mandatory access control system, relies on meticulously defined security policies to enforce the principle of least privilege, thereby preventing unauthorized access and bolstering system integrity. However, the sheer volume of policy rules and their intricate semantics make manual configuration a time-consuming, expertise-intensive, and error-prone endeavor.

This paper proposes CASPR (Context-Aware Security Policy Recommendation), a system designed to recommend appropriate policy modifications and detect anomalies within existing or newly generated rules. CASPR leverages four distinct types of context-aware information—policy rules, file locations, audit logs, and attributes—to compute privilege similarity and guide its recommendations. By employing a K-means clustering model, including a novel secondary clustering step for object types, CASPR aims to significantly reduce the manual effort required for policy customization, mitigate the risk of over-privileging (which can lead to unauthorized access and data leakage), and prevent under-privileging (which can disrupt normal system operations). The research underscores the critical importance of accurate policy configuration in maintaining robust system security and operational continuity.

Background

▶ Watch: Introduction to SE Nix and policy configuration challenges (0:00)

SE Linux is a fundamental component in many modern Linux distributions, providing a powerful Mandatory Access Control (MAC) mechanism that extends beyond traditional Discretionary Access Control (DAC). Its core function is to control interactions between entities (subjects and objects) through a granular system of security labels and security policies. Each entity in an access request is assigned a label, and the policy dictates privilege changes based on the types defined in these labels. The objective is to achieve least privilege, ensuring that entities only possess the minimum permissions necessary to perform their intended functions, thereby preventing unauthorized access and containing potential breaches.

Despite its capabilities, the practical implementation and maintenance of SE Linux policies present significant hurdles. A typical SE Linux policy comprises a vast number of rules, and their interdependencies and semantic complexities are formidable. Manually configuring these policies demands deep expertise, is time-consuming, and is highly susceptible to human error. This problem is exacerbated when dealing with newly defined types, for which no reference rules exist, making policy generation from scratch particularly challenging.

The consequences of improperly configured policies are severe. Over-privileging, where entities are granted more permissions than required, creates a larger attack surface. This can lead to critical security vulnerabilities such as unauthorized data access, data leakage, and the facilitation of malicious attacks or privilege escalation. Conversely, under-privileging, where necessary permissions are withheld, can disrupt the normal operation of the system, causing applications to fail or services to become unavailable. Previous research has attempted to address policy analysis and automatic rule recommendation, but many existing works fall short in providing effective recommendations for newly defined types, which inherently lack historical data or existing rules as a reference point. CASPR aims to bridge this gap by integrating comprehensive context-aware information to make more informed and robust policy recommendations.

Key Findings

▶ Watch: Methodology: using context-aware features with K-means clustering (2:50)

The research presented in this talk makes several significant contributions to the field of automated security policy management. The primary finding is the innovative introduction and integration of context-aware information for more accurate privilege computation and policy recommendation. By considering multiple dimensions of context, CASPR moves beyond simplistic rule-matching to infer deeper privilege similarities.

The core of the findings revolves around the CASPR framework itself, which is a comprehensive method for both policy recommendation and anomaly detection. It demonstrates that a K-means clustering model, when applied to domains and object types using a rich set of context-aware features, can effectively identify groups of entities that share similar privilege requirements. A particularly noteworthy finding is the necessity and efficacy of secondary clustering for objects, which refines the grouping by acknowledging that objects of the same type might still possess distinct privilege sets if they belong to different higher-level classes.

Experimentally, CASPR proves to be highly effective, achieving an impressive 92.44% accuracy in recommending policy rules under optimal conditions. This performance significantly outperforms other baseline policy recommendation methods, demonstrating its superior adaptability and feasibility across various operating systems. Furthermore, CASPR's integrated anomaly detection component is shown to be capable of identifying genuine security flaws; out of 97,583 recommended rules, 168 anomalies were successfully identified, highlighting its practical utility in enhancing policy integrity and preventing misconfigurations that could lead to vulnerabilities. The research thus confirms that a context-aware, clustering-based approach can substantially automate and improve the security posture of SE Linux environments.

Technical Deep Dive

▶ Watch: Anomaly detection for policy integrity and completeness (4:40)

CASPR's technical foundation rests on its innovative use of context-aware information to compute privilege similarity, which then informs its policy recommendation and anomaly detection processes. The system integrates four key types of contextual data:

  1. Policy Rules: These are considered the most direct indicators of privilege. If a subject is granted permission for a particular object via an existing policy rule, it directly implies a privilege relationship. In the feature vector construction, the corresponding value for such a direct grant is set to one.
  2. File Locations (Path Dependencies): Subjects that exhibit past dependencies on specific file locations are assumed to share similar privileges. The rationale is that processes interacting with the same sensitive directories or files often require similar access rights.
  3. Audit Logs (Frequent Simultaneous Access): The system analyzes audit logs to identify behaviors that occur simultaneously, suggesting they are caused by the same underlying event. If entities are consistently allowed or denied access together, they likely share similar privilege requirements.
  4. Attributes: SE Linux uses attributes to group types with similar functional purposes. Permissions granted with an attribute as a unit imply that all contained types share a functional similarity, and thus, similar privilege needs.

These four dimensions of context are used to construct feature vectors for both domains (subjects) and object types. For each feature, if the corresponding indicator exists (e.g., a policy rule grants permission, a past dependency is found, simultaneous access is observed, or an entity belongs to a shared attribute), the value in the feature vector is set to one. After calculating similarities across multiple dimensions, these values undergo standardization and normalization to ensure fair comparison and prevent any single feature from dominating the similarity calculation.

The normalized feature vectors then serve as input for a K-means clustering model. CASPR applies K-means separately to cluster domains and object types. The objective of this clustering is to group entities whose privilege sets are most identical based on the feature vectors.

A critical technical refinement in CASPR is the implementation of secondary clustering specifically for objects. The rationale behind this is insightful: while two objects might share the same generic object type, their actual privilege requirements could differ significantly if they are contained within different higher-level classes or contexts. For instance, two 'log files' in an SE Linux system might have different access policies depending on whether they belong to a 'web server' class or a 'database server' class. This secondary clustering step ensures that the system does not recommend overly broad rules that ignore these subtle but important contextual differences, thereby preventing both over-privileging and under-privileging. After obtaining the primary and secondary clustering results, CASPR generates separate lists of recommended rules based on each cluster and then calculates their intersection. This intersection approach is vital to prevent "battling recommending rules" by ensuring that only rules consistent across related clusters are proposed, thus ignoring minor differences that might lead to conflicts.

Beyond recommendation, CASPR incorporates a robust anomaly detection mechanism to enhance policy integrity and availability. This component identifies and refines anomalies by examining attributes, path dependencies, and permission sets. The types of anomalies detected include:

  • Constraint Conflicts: Violations of defined constraints within the policy.
  • Policy Inconsistencies: Contradictory rules or permissions that undermine the policy's logic.
  • Permission Incompleteness: Scenarios where necessary rules are missing for an operation to perform correctly, leading to system failures.

By addressing these anomalies, CASPR ensures that the recommended policies are not only accurate but also robust, complete, and free from internal conflicts, thereby guaranteeing the necessary rules for expected system behaviors.

The system's performance was evaluated by employing CASPR in six different operating systems. This broad application demonstrated its scalability and adaptability, even with the large number of rules typically found in SE Linux policies. The analysis of clustering results, aided by the SHAP (SHapley Additive exPlanations) interpretable program, revealed that the "policy feature" (direct rule grants) is generally the most decisive factor in determining identical privileges. However, when clustering new types, where direct policy rules are absent, the "attribute feature" shows a reduced contribution, indicating the challenge of new type policy generation and the need for the other context features to compensate.

Demo / Proof of Concept

▶ Watch: Achieved 92.44% accuracy, outperforming other recommendation methods (6:50)

While the talk does not describe a live demonstration of CASPR in action, it details the comprehensive experimental evaluation performed to validate its effectiveness. The researchers "employ CSPR in six operating systems to illustrate it," indicating a thorough testing phase across diverse real-world environments. This evaluation served as the proof of concept for CASPR's design and capabilities.

The experimental setup involved:

  1. Attribute Extensions: Enhancing existing policy rules with attribute information.
  2. Data Cleaning: Removing duplicate and irrelevant data to obtain a clean set of privileges for each system.

The results of these evaluations demonstrated that CASPR's performance is "satisfying," with an "average efficiency" that indicates its scalability and adaptability across different SE Linux policy versions. The clustering results showed an "apparent clustering effect" for both domains and object types, confirming the model's ability to group similar entities. Crucially, the system achieved a peak accuracy of 92.44% in recommending policy rules, even acknowledging a "few false samples." This high accuracy, despite the inherent complexity of SE Linux policies and the challenge of new types (where accuracy was slightly lower due to the absence of the crucial policy feature), serves as the primary proof of concept for CASPR's practical utility. The successful identification of 168 anomalies out of 97,583 recommended rules further validates its anomaly detection capabilities. The comparison against "other two policy recommendation methods" confirmed that CASPR "outperforms baseline measures," providing strong evidence of its superior design and implementation.

Defensive Implications

▶ Watch: Summary of contributions: context-aware information, CASPR method, experiments (8:00)

CASPR offers significant defensive implications for organizations grappling with the complexities of SE Linux policy management and the broader challenge of maintaining a secure system posture. By automating the recommendation and refinement of security policies, defenders can achieve several critical advantages:

  1. Reduced Attack Surface: The primary goal of SE Linux is to enforce least privilege. CASPR directly contributes to this by identifying and recommending appropriate, minimal permissions. By addressing over-privileging, it actively narrows the attack surface, making it harder for attackers to exploit vulnerabilities or escalate privileges even if they gain initial access.
  2. Enhanced Policy Integrity and Availability: The anomaly detection component is crucial for ensuring that policies are not only secure but also functional. By identifying constraint conflicts, policy inconsistencies, and permission incompleteness, CASPR helps prevent situations where legitimate system operations are blocked due to under-privileging, thereby maintaining system availability. Simultaneously, it eliminates conflicting rules that could be exploited.
  3. Faster and More Reliable Policy Deployment: Manual policy configuration is slow and error-prone. CASPR's automation capabilities drastically reduce the time and effort required to configure and update policies, especially for newly defined types. This allows organizations to deploy new applications or services more quickly without compromising security, and to respond more agilely to evolving threat landscapes.
  4. Reduced Reliance on Expertise: The need for deep SE Linux expertise is a significant barrier for many organizations. CASPR lowers this barrier by providing intelligent, context-aware recommendations. While human oversight remains important, the system streamlines the process, allowing security teams to focus on higher-level architectural decisions rather than granular rule crafting.
  5. Proactive Vulnerability Mitigation: By automatically recommending refined policies and detecting anomalies, CASPR acts as a proactive defense mechanism. It helps identify potential misconfigurations before they can be exploited, moving security from a reactive to a more preventive stance.
  6. Scalability and Adaptability: The evaluation across six operating systems demonstrates CASPR's ability to handle diverse environments and large rule sets. This scalability means that even large enterprises with complex infrastructures can leverage CASPR to manage their SE Linux policies effectively.

In essence, CASPR empowers defenders to implement and maintain stronger, more consistent, and more efficient SE Linux policies, directly contributing to a more resilient and secure computing environment.

Key Takeaways

  • Automation of SE Linux Policy Management: CASPR provides an automated method for recommending and refining complex SE Linux security policies, significantly reducing the manual effort, time, and expertise traditionally required.
  • Context-Aware Privilege Computation: The system innovatively integrates four types of context-aware information—policy rules, file locations, audit logs, and attributes—to accurately compute privilege similarity, which is crucial for informed policy recommendations.
  • Advanced Clustering for Granular Control: CASPR utilizes a K-means clustering model for domains and object types, featuring a novel secondary clustering for objects to ensure fine-grained privilege assignment, preventing both over- and under-privileging.
  • Robust Anomaly Detection: An integral component of CASPR is its ability to detect grammar and semantic anomalies, including constraint conflicts, policy inconsistencies, and permission incompleteness, enhancing policy integrity and system availability.
  • High Accuracy and Superior Performance: CASPR achieves a high accuracy rate of 92.44% in policy rule recommendation and demonstrably outperforms other baseline methods, proving its effectiveness and adaptability across multiple operating systems.
  • Reduced Attack Surface and Improved Security Posture: By recommending least-privilege policies and identifying misconfigurations, CASPR directly contributes to narrowing the attack surface and bolstering the overall security posture of SE Linux-enabled systems.

About the Speaker(s)

The presentation for "CASPR: Context-Aware Security Policy Recommendation" was delivered by Ken from the University of Chinese Academy of Sciences. Ken presented the work on behalf of the original authors, who were unable to attend. The primary author, as indicated in the talk metadata, is Lifang Xiao. Both Ken and the authors are affiliated with the University of Chinese Academy of Sciences, where this research on advanced security policy recommendation and anomaly detection was conducted.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Competent academic systems security paper solving a real and underserved problem — SELinux policy automation is genuinely painful and the context-aware clustering approach is a credible contribution. The 92.44% accuracy headline and anomaly detection results are reasonable for an NDSS-caliber paper, but this doesn't push the envelope enough to be memorable, and the presentation (a proxy delivery on behalf of absent authors) limits the ceiling.

Heather Calloway (CISO) — WEAK

Technically credible academic work on automating SELinux policy configuration, but it never crosses into operator or institutional relevance. The 92% accuracy claim is presented without the failure analysis that actually matters to defenders, and there's no path from research to deployment.

→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025

All talks from Network and Distributed System Security (NDSS) Symposium 2025