Learning Relationship-Based Access Control Policies from Black-Box Systems

Learning Relationship-Based Access Control Policies from Black-Box Systems
复制标题

DOI:
10.1145/3517121
复制
发表时间:
2022-08-01
影响因子:
2.3
通讯作者:
Masoumzadeh,Amirreza
Masoumzadeh,Amirreza
中科院分区:
计算机科学4区
文献类型:
--
作者:
Iyer,Padmavathi;Masoumzadeh,Amirreza

文献摘要

被引文献

相似文献

访问控制策略在信息系统中保护数据安全方面至关重要。不幸的是,通常情况下,这些策略的文档记录得很差,并且它们的规范和实现之间的差距阻止了系统用户,甚至其开发人员,理解系统的整体强制策略。为了解决这个问题,我们提出了第一种系统的方法,通过与目标系统进行交互并将其视为黑匣子来学习强制授权。目标系统的黑盒视图具有学习其整体访问控制策略的优势,而无需处理其内部设计复杂性。此外,与以前的文献相比,政策挖掘和政策推断,我们避免了详尽的探索授权空间,最大限度地减少我们的意见。我们专注于学习基于关系的访问控制(ReBAC)政策,并展示了我们如何可以构建一个确定性有限自动机(DFA),正式表征这样一个强制执行的政策。我们从理论上分析我们提出的学习方法,通过研究其终止性,正确性和复杂性。此外,我们进行了广泛的实验分析的基础上,现实的应用场景,以建立其成本,学习质量,并在实践中的可扩展性。
Access control policies are crucial in securing data in information systems. Unfortunately, often times, such policies are poorly documented, and gaps between their specification and implementation prevent the system users, and even its developers, from understanding the overall enforced policy of a system. To tackle this problem, we propose the first of its kind systematic approach for learning the enforced authorizations from a target system by interacting with and observing it as a black box. The black-box view of the target system provides the advantage of learning its overall access control policy without dealing with its internal design complexities. Furthermore, compared to the previous literature on policy mining and policy inference, we avoid exhaustive exploration of the authorization space by minimizing our observations. We focus on learning relationship-based access control (ReBAC) policy, and show how we can construct a deterministic finite automaton (DFA) to formally characterize such an enforced policy. We theoretically analyze our proposed learning approach by studying its termination, correctness, and complexity. Furthermore, we conduct extensive experimental analysis based on realistic application scenarios to establish its cost, quality of learning, and scalability in practice.