PRUCC-RM: Permission-Role-Usage Cardinality Constrained Role Mining

PRUCC-RM: Permission-Role-Usage Cardinality Constrained Role Mining
复制标题

DOI:
10.1109/compsac.2017.195
复制
发表时间:
2017-07
期刊:
2017 IEEE 41st Annual Computer Software and Applications Conference (COMPSAC)
影响因子:
--
通讯作者:
C. Blundo;S. Cimato;Luisa Siniscalchi
C. Blundo;S. Cimato;Luisa Siniscalchi
中科院分区:
其他
文献类型:
--
作者:
C. Blundo;S. Cimato;Luisa Siniscalchi

文献摘要

被引文献

相似文献

基于角色的访问控制(RBAC)模型已被许多组织采用,作为实现安全策略和将受限资源的访问权分配给角色、将角色分配给用户的标准方法。为了捕获组织内的业务关系并有效地迁移到RBAC,已经定义了几种角色挖掘技术。可以对生成的角色和对用户的分配施加约束,以过滤掉自动算法产生的不一致情况,并更好地捕获组织的状态。在本文中,我们感兴趣的是对角色中可以包含的权限数量和角色可以分配给的人员数量的约束。我们分析了这个问题,并提出了一些启发方法。启发式方法已应用于标准数据集,以验证其性能。
Role Based Access Control (RBAC) models have been adopted in many organizations as the standard way to implement security policies and assign access to restricted resources to roles and roles to users. To capture the business relationships within the organization and efficiently migrate towards RBAC, several role mining techniques have been defined. Constraints on the resulting roles and assignments to users can be imposed to filter out inconsistent situations produced by the automatic algorithm and to better capture the status of the organization. In this paper we are interested in constraints on the number of permissions that can be included in a role and on the number of persons a role can be assigned to. We analyze the problem and propose a couple of heuristics. The heuristics have been applied to standard datasets to validate their performance.