PolTree: A Data Structure for Making Efficient Access Decisions in ABAC

PolTree: A Data Structure for Making Efficient Access Decisions in ABAC
复制标题

PolTree:ABAC 中用于做出高效访问决策的数据结构

DOI:
10.1145/3322431.3325102
复制
发表时间:
2019
期刊:
Proceedings of the 24th ACM Symposium on Access Control Models and Technologies
影响因子:
--
通讯作者:
Atluri, Vijay
Atluri, Vijay
中科院分区:
--
文献类型:
--
作者:
Nath, Ronit;Das, Saptarshi;Sural, Shamik;Vaidya, Jaideep;Atluri, Vijay

文献摘要

参考文献

被引文献

相似文献

在ABAC (Attribute-Based Access Control)中,根据用户、对象和环境等不同类型实体的属性值,制定一组规则(统称为ABAC Policy),允许或拒绝用户访问某个对象。因此,有效地评估这些规则对于确保在访问请求到来时以在线速度做出决策至关重要。顺序地评估策略中的所有规则本质上是耗时的,并且不随ABAC系统的大小或访问请求的频率而扩展。这个问题,这是相当相关的实际部署ABAC,令人惊讶的是,迄今为止还没有在文献中解决。在本文中,我们引入了用于表示ABAC策略的树数据结构的两个变体,我们将其命名为PolTree。在二进制版本(B-PolTree)中,在每个节点上,根据是否满足特定的属性值对做出决策。另一方面,n元版本(N-PolTree)从给定节点中生长出的分支数量与在该节点上检查属性的可能值的总数相同。不同数据集的广泛实验评估表明了该方法的可扩展性和有效性。
In Attribute-Based Access Control (ABAC), a user is permitted or denied access to an object based on a set of rules (together called an ABAC Policy) specified in terms of the values of attributes of various types of entities, namely, user, object and environment. Efficient evaluation of these rules is therefore essential for ensuring decision making at on-line speed when an access request comes. Sequentially evaluating all the rules in a policy is inherently time consuming and does not scale with the size of the ABAC system or the frequency of access requests. This problem, which is quite pertinent for practical deployment of ABAC, surprisingly has not so far been addressed in the literature. In this paper, we introduce two variants of a tree data structure for representing ABAC policies, which we name as PolTree. In the binary version (B-PolTree), at each node, a decision is taken based on whether a particular attribute-value pair is satisfied or not. The n-ary version (N-PolTree), on the other hand, grows as many branches out of a given node as the total number of possible values for the attribute being checked at that node. An extensive experimental evaluation with diverse data sets shows the scalability and effectiveness of the proposed approach.
DOI: 10.1109/inm.2003.1194157
发表时间: 2003-03
期刊: IFIP/IEEE Eighth International Symposium on Integrated Network Management, 2003.
影响因子: --
作者:
E. Al-Shaer;H. Hamed
通讯作者: E. Al-Shaer;H. Hamed
模型检查防火墙策略配置
DOI: --
发表时间: 2009
期刊: IEEE International Symposium on Policies for Distributed Systems and Networks
影响因子: --
作者:
A. Jeffrey;T. Samak
通讯作者: T. Samak
高速防火墙策略验证的策略映射算法
DOI: --
发表时间: 2016
期刊: International Journal of Network Security
影响因子: --
作者:
Suchart Khummanee;Kitt Tientanopajai
通讯作者: Kitt Tientanopajai
使用基尼不纯度挖掘具有环境属性的基于属性的访问控制策略
DOI: --
发表时间: 2018
期刊: ACM Symposium on Access Control Models and Technologies
影响因子: --
作者:
Saptarshi Das;S. Sural;Jaideep Vaidya;V. Atluri
通讯作者: V. Atluri
DOI: 10.1109/locs.2018.2889980
发表时间: 2018-07-01
期刊: IEEE letters of the Computer Society
影响因子: --
作者:
Das, Saptarshi;Sural, Shamik;Atluri, Vijayalakshmi
通讯作者: Atluri, Vijayalakshmi