Mining Relationship-Based Access Control Policies

Mining Relationship-Based Access Control Policies
复制标题

挖掘基于关系的访问控制策略

DOI:
10.1145/3078861.3078878
复制
发表时间:
2017
期刊:
Proceedings of the 22nd ACM on Symposium on Access Control Models and Technologies
影响因子:
--
通讯作者:
Jiajie Li
Jiajie Li
中科院分区:
--
文献类型:
--
作者:
Thang Bui;S. Stoller;Jiajie Li

文献摘要

被引文献

相似文献

基于关系的访问控制(ReBAC)提供了高度的表现力和灵活性,促进了安全性和信息共享。我们将ReBAC描述为基于属性的访问控制(ABAC)的面向对象扩展,其中关系用引用其他对象的字段来表示,路径表达式用来跟踪对象之间的关系链。通过从现有访问控制策略和属性数据部分自动化ReBAC策略的开发,ReBAC策略挖掘算法具有显著降低从传统访问控制系统迁移到ReBAC的成本的潜力。提出了一种从对象模型表示的访问控制列表(ACL)和属性数据中挖掘ReBAC策略的算法,并在4个策略样本和2个大型案例上对该算法进行了评估。该算法适用于从访问日志和对象模型中挖掘ReBAC策略。这是解决这些问题的第一个算法。
Relationship-based access control (ReBAC) provides a high level of expressiveness and flexibility that promotes security and information sharing. We formulate ReBAC as an object-oriented extension of attribute-based access control (ABAC) in which relationships are expressed using fields that refer to other objects, and path expressions are used to follow chains of relationships between objects. ReBAC policy mining algorithms have potential to significantly reduce the cost of migration from legacy access control systems to ReBAC, by partially automating the development of a ReBAC policy from an existing access control policy and attribute data. This paper presents an algorithm for mining ReBAC policies from access control lists (ACLs) and attribute data represented as an object model, and an evaluation of the algorithm on four sample policies and two large case studies. Our algorithm can be adapted to mine ReBAC policies from access logs and object models. It is the first algorithm for these problems.