Relation extraction for inferring access control rules from natural language artifacts

Relation extraction for inferring access control rules from natural language artifacts
复制标题

DOI:
10.1145/2664243.2664280
复制
发表时间:
2014-12
期刊:
Proceedings of the 30th Annual Computer Security Applications Conference
影响因子:
--
通讯作者:
John Slankas;Xusheng Xiao;L. Williams;Tao Xie
John Slankas;Xusheng Xiao;L. Williams;Tao Xie
中科院分区:
其他
文献类型:
--
作者:
John Slankas;Xusheng Xiao;L. Williams;Tao Xie

文献摘要

被引文献

相似文献

经过四十多年的使用和改进,访问控制(通常以访问控制规则(ACR)的形式)仍然是信息安全的重要控制机制。然而,ACR通常要么隐藏在现有的自然语言(NL)工件中,要么从主题专家那里引出。为了解决第一种情况,我们的研究目标是帮助开发人员实现ACR推断ACR从NL文物。为了帮助规则推理,我们提出了一种提取关系的方法(即,两个或多个项目之间的关系)。与现有的方法不同,我们的方法结合了信息提取和机器学习的技术。我们开发了一个迭代算法来发现句子中代表ACR的模式。我们在整个文档中使用与主题-动作-资源模式匹配的频繁出现的名词来播种该算法。然后,该算法搜索这些名词的其他组合,以发现其他模式。我们评估我们的方法,从三个系统的文件在三个领域:会议管理,教育和医疗保健。我们的评估结果表明,ACR存在于47%的句子中,我们的方法有效地识别这些ACR句子,准确率为81%,召回率为65%;我们的方法从这些识别的ACR句子中提取ACR,平均准确率为76%,平均召回率为49%。
With over forty years of use and refinement, access control, often in the form of access control rules (ACRs), continues to be a significant control mechanism for information security. However, ACRs are typically either buried within existing natural language (NL) artifacts or elicited from subject matter experts. To address the first situation, our research goal is to aid developers who implement ACRs by inferring ACRs from NL artifacts. To aid in rule inference, we propose an approach that extracts relations (i.e., the relationship among two or more items) from NL artifacts such as requirements documents. Unlike existing approaches, our approach combines techniques from information extraction and machine learning. We develop an iterative algorithm to discover patterns that represent ACRs in sentences. We seed this algorithm with frequently occurring nouns matching a subject--action--resource pattern throughout a document. The algorithm then searches for additional combinations of those nouns to discover additional patterns. We evaluate our approach on documents from three systems in three domains: conference management, education, and healthcare. Our evaluation results show that ACRs exist in 47% of the sentences, and our approach effectively identifies those ACR sentences with a precision of 81% and recall of 65%; our approach extracts ACRs from those identified ACR sentences with an average precision of 76% and an average recall of 49%.