Synthesizing and Analyzing Attribute-Based Access Control Model Generated from Natural Language Policy Statements
Synthesizing and Analyzing Attribute-Based Access Control Model Generated from Natural Language Policy Statements
复制标题
综合和分析从自然语言策略语句生成的基于属性的访问控制模型
DOI:
10.1145/3589608.3593844
复制
发表时间:
2023
期刊:
影响因子:
--
通讯作者:
Shirazi, Hosein
中科院分区:
文献类型:
--
作者:
Abdelgawad, Mahmoud;Ray, Indrakshi;Alqurashi, Saja;Venkatesha, Videep;Shirazi, Hosein
Access control policies (ACPs) are natural language statements that describe criteria under which users can access resources. We focus on constructing NIST Next Generation Access Control (NGAC) ABAC model from ACP statements. NGAC is more complex than RBAC or XACML ABAC as it supports dynamic, event-based policies, as well as prohibitions. We provide algorithms that use spaCy, a NLP library, to extract entities and relations from ACP sentences and convert them into the NGAC model. We then convert this NGAC model into Neo4j representation for the purpose of analysis. We apply the approach to various real-world ACP datasets to demonstrate the feasibility and assess scalability. We demonstrate that the approach is scalable and effectively extracts the NGAC ABAC model from large ACP datasets. We also show that redundancies and inconsistencies of ACP sentences are often found in unclean datasets.
DOI:
10.1145/2664243.2664280
发表时间:
2014-12
期刊:
Proceedings of the 30th Annual Computer Security Applications Conference
影响因子:
--
作者:
John Slankas;Xusheng Xiao;L. Williams;Tao Xie
通讯作者:
John Slankas;Xusheng Xiao;L. Williams;Tao Xie