Greedy and evolutionary algorithms for mining relationship-based access control policies

Greedy and evolutionary algorithms for mining relationship-based access control policies
复制标题

DOI:
10.1016/j.cose.2018.09.011
复制
发表时间:
2019-01-01
影响因子:
5.6
通讯作者:
Li, Jiajie
Li, Jiajie
中科院分区:
计算机科学3区
文献类型:
--
作者:
Bui, Thang;Stoller, Scott D.;Li, Jiajie

文献摘要

被引文献

相似文献

基于关系的访问控制 (ReBAC) 提供了高水平的表达性和灵活性,可促进安全性和信息共享。我们将 ReBAC 制定为基于属性的访问控制(ABAC)的面向对象扩展,其中使用引用其他对象的字段来表达关系,并使用路径表达式来遵循对象之间的关系链。 ReBAC 策略挖掘算法可以通过部分自动化从现有访问控制策略和属性数据开发 ReBAC 策略,从而显着降低从遗留访问控制系统迁移到 ReBAC 的成本。本文提出了两种从访问控制列表(ACL)和表示为对象模型的属性数据中挖掘 ReBAC 策略的算法:启发式引导的贪婪算法和基于语法的进化算法。对四个样本政策和两个大型案例研究的算法评估证明了它们的有效性。 (C) 2018 Elsevier Ltd. 保留所有权利。
Relationship-based access control (ReBAC) provides a high level of expressiveness and flexibility that promotes security and information sharing. We formulate ReBAC as an object-oriented extension of attribute-based access control (ABAC) in which relationships are expressed using fields that refer to other objects, and path expressions are used to follow chains of relationships between objects. ReBAC policy mining algorithms have potential to significantly reduce the cost of migration from legacy access control systems to ReBAC, by partially automating the development of a ReBAC policy from an existing access control policy and attribute data. This paper presents two algorithms for mining ReBAC policies from access control lists (ACLs) and attribute data represented as an object model: a greedy algorithm guided by heuristics, and a grammar-based evolutionary algorithm. An evaluation of the algorithms on four sample policies and two large case studies demonstrates their effectiveness. (C) 2018 Elsevier Ltd. All rights reserved.