Mining Relationship-Based Access Control Policies from Incomplete and Noisy Data
Mining Relationship-Based Access Control Policies from Incomplete and Noisy Data
复制标题
从不完整和噪声数据中挖掘基于关系的访问控制策略
DOI:
10.1007/978-3-030-18419-3_18
复制
发表时间:
2018
期刊:
影响因子:
--
通讯作者:
Jiajie Li
中科院分区:
文献类型:
--
作者:
Thang Bui;S. Stoller;Jiajie Li
Relationship-based access control (ReBAC) extends attribute-based access control (ABAC) to allow policies to be expressed in terms of chains of relationships between entities. ReBAC policy mining algorithms have potential to significantly reduce the cost of migration from legacy access control systems to ReBAC, by partially automating the development of a ReBAC policy. This paper presents algorithms for mining ReBAC policies from information about entitlements together with information about entities. It presents the first such algorithms designed to handle incomplete information about entitlements, typically obtained from operation logs, and noise (errors) in information about entitlements. We present two algorithms: a greedy search guided by heuristics, and an evolutionary algorithm. We demonstrate the effectiveness of the algorithms on several policies, including 3 large case studies.