Synthesizing and Analyzing Attribute-Based Access Control Model Generated from Natural Language Policy Statements

Synthesizing and Analyzing Attribute-Based Access Control Model Generated from Natural Language Policy Statements
复制标题

综合和分析从自然语言策略语句生成的基于属性的访问控制模型

DOI:
10.1145/3589608.3593844
复制
发表时间:
2023
期刊:
ACM
影响因子:
--
通讯作者:
Shirazi, Hosein
Shirazi, Hosein
中科院分区:
--
文献类型:
--
作者:
Abdelgawad, Mahmoud;Ray, Indrakshi;Alqurashi, Saja;Venkatesha, Videep;Shirazi, Hosein

文献摘要

参考文献

被引文献

相似文献

访问控制策略(acp)是描述用户访问资源的标准的自然语言语句。重点研究了基于ACP语句构建NIST下一代访问控制(NGAC) ABAC模型。NGAC比RBAC或XACML ABAC更复杂,因为它支持动态的、基于事件的策略以及禁止。我们提供了使用NLP库spaCy从ACP句子中提取实体和关系并将其转换为NGAC模型的算法。然后,为了分析的目的,我们将这个NGAC模型转换为Neo4j表示。我们将该方法应用于各种现实世界的ACP数据集,以证明可行性和评估可扩展性。我们证明了该方法具有可扩展性,并且可以有效地从大型ACP数据集中提取NGAC ABAC模型。我们还表明,在不干净的数据集中经常发现ACP句子的冗余和不一致。
Access control policies (ACPs) are natural language statements that describe criteria under which users can access resources. We focus on constructing NIST Next Generation Access Control (NGAC) ABAC model from ACP statements. NGAC is more complex than RBAC or XACML ABAC as it supports dynamic, event-based policies, as well as prohibitions. We provide algorithms that use spaCy, a NLP library, to extract entities and relations from ACP sentences and convert them into the NGAC model. We then convert this NGAC model into Neo4j representation for the purpose of analysis. We apply the approach to various real-world ACP datasets to demonstrate the feasibility and assess scalability. We demonstrate that the approach is scalable and effectively extracts the NGAC ABAC model from large ACP datasets. We also show that redundancies and inconsistencies of ACP sentences are often found in unclean datasets.
DOI: 10.1145/2664243.2664280
发表时间: 2014-12
期刊: Proceedings of the 30th Annual Computer Security Applications Conference
影响因子: --
作者:
John Slankas;Xusheng Xiao;L. Williams;Tao Xie
通讯作者: John Slankas;Xusheng Xiao;L. Williams;Tao Xie