Optimal Employee Recruitment in Organizations under Attribute-Based Access Control

Optimal Employee Recruitment in Organizations under Attribute-Based Access Control
复制标题

DOI:
10.1145/3403950
复制
发表时间:
2021-01
期刊:
ACM Transactions on Management Information Systems (TMIS)
影响因子:
--
通讯作者:
Arindam Roy;S. Sural;A. Majumdar;Jaideep Vaidya;V. Atluri
Arindam Roy;S. Sural;A. Majumdar;Jaideep Vaidya;V. Atluri
中科院分区:
其他
文献类型:
--
作者:
Arindam Roy;S. Sural;A. Majumdar;Jaideep Vaidya;V. Atluri

文献摘要

相似文献

对于任何成功的业务奋进,招聘所需数量的适当资格的员工在适当的职位是一个关键要求。为了有效地利用人力资源,重新安排这种工作人员的分配也是一项极为重要的任务。这包括表现不佳的员工必须由新申请人替换的情况。通常,申请职位的候选人数量很大,因此,识别最佳子集的任务变得至关重要。此外,人力资源经理亦希望利用员工退休的机会,改善人力资源的运用。但是,安全策略强制执行的约束禁止将任何任务任意分配给员工。此外,新员工应具备处理分配任务所需的能力。在这篇文章中,我们将这个问题形式化为最优招聘问题(ORP),其中的目标是从一组候选人中选择最少数量的新员工来填补即将离职的员工所创建的空缺职位,同时确保满足指定的安全条件。用于规范授权策略和约束的模型是基于属性的访问控制(ABAC),因为它被认为是处理组织安全策略的事实上的下一代框架。我们证明了ORP问题是NP-难的,并提出了一种贪婪启发式算法来解决它。大量的实验评估表明了所提出的解决方案的有效性和效率。
For any successful business endeavor, recruitment of a required number of appropriately qualified employees in proper positions is a key requirement. For effective utilization of human resources, reorganization of such workforce assignment is also a task of utmost importance. This includes situations when the under-performing employees have to be substituted with fresh applicants. Generally, the number of candidates applying for a position is large, and hence, the task of identifying an optimal subset becomes critical. Moreover, a human resource manager would also like to make use of the opportunity of retirement of employees to improve manpower utilization. However, the constraints enforced by the security policies prohibit any arbitrary assignment of tasks to employees. Further, the new employees should have the capabilities required to handle the assigned tasks. In this article, we formalize this problem as the Optimal Recruitment Problem (ORP), wherein the goal is to select the minimum number of fresh employees from a set of candidates to fill the vacant positions created by the outgoing employees, while ensuring satisfiability of the specified security conditions. The model used for specification of authorization policies and constraints is Attribute-Based Access Control (ABAC), since it is considered to be the de facto next-generation framework for handling organizational security policies. We show that the ORP problem is NP-hard and propose a greedy heuristic for solving it. Extensive experimental evaluation shows both the effectiveness and efficiency of the proposed solution.