Mining Relationship-Based Access Control Policies from Incomplete and Noisy Data

Mining Relationship-Based Access Control Policies from Incomplete and Noisy Data
复制标题

从不完整和噪声数据中挖掘基于关系的访问控制策略

DOI:
10.1007/978-3-030-18419-3_18
复制
发表时间:
2018
期刊:
Proceedings of the Eleventh ACM Conference on Data and Application Security and Privacy
影响因子:
--
通讯作者:
Jiajie Li
Jiajie Li
中科院分区:
--
文献类型:
--
作者:
Thang Bui;S. Stoller;Jiajie Li

文献摘要

被引文献

相似文献

基于关系的访问控制(ReBAC)扩展了基于属性的访问控制(ABAC),允许用实体之间的关系链来表示策略。通过部分自动化ReBAC策略的开发,ReBAC策略挖掘算法有可能显著降低从传统访问控制系统迁移到ReBAC的成本。本文提出了从授权信息和实体信息中挖掘ReBAC策略的算法。它提出了第一个这样的算法,用于处理关于授权的不完整信息(通常从操作日志中获得)和关于授权的信息中的噪声(错误)。提出了两种算法:一种是启发式的贪婪搜索算法,另一种是进化算法。我们展示了算法在几个策略上的有效性,包括3个大型案例研究。
Relationship-based access control (ReBAC) extends attribute-based access control (ABAC) to allow policies to be expressed in terms of chains of relationships between entities. ReBAC policy mining algorithms have potential to significantly reduce the cost of migration from legacy access control systems to ReBAC, by partially automating the development of a ReBAC policy. This paper presents algorithms for mining ReBAC policies from information about entitlements together with information about entities. It presents the first such algorithms designed to handle incomplete information about entitlements, typically obtained from operation logs, and noise (errors) in information about entitlements. We present two algorithms: a greedy search guided by heuristics, and an evolutionary algorithm. We demonstrate the effectiveness of the algorithms on several policies, including 3 large case studies.