Effective Evaluation of Relationship-Based Access Control Policy Mining

Effective Evaluation of Relationship-Based Access Control Policy Mining
复制标题

基于关系的访问控制策略挖掘的有效评估

DOI:
10.1145/3532105.3535022
复制
发表时间:
2022
期刊:
Proceedings of the 27th ACM Symposium on Access Control Models and Technologies
影响因子:
--
通讯作者:
Masoumzadeh, Amirreza
Masoumzadeh, Amirreza
中科院分区:
--
文献类型:
--
作者:
Iyer, Padmavathi;Masoumzadeh, Amirreza

文献摘要

参考文献

被引文献

相似文献

基于关系的访问控制策略的挖掘算法生成由基于关系的模式组成的策略,这些模式根据给定的系统图证明输入授权的合理性。策略挖掘算法的正确功能通常是基于实验评估来测试的,在每个实验评估中,向矿工提供一组授权和系统图,并期望生成相应的地面实况策略。在本文中,我们提出了在评估测试中系统图和地面实况策略之间必须存在的形式属性,以便矿工面临产生精确的地面实况策略的挑战。我们表明,在实验中未能验证这些属性会导致评估不充分,即没有真正测试矿工是否能够处理地面真实策略的复杂性。我们还认为,遵循这些属性将在评估中提供计算优势。我们提出算法来识别和纠正系统图中违反这些属性的行为。我们还通过一系列实验研究展示了我们对这些属性及其实施的观察。
Mining algorithms for relationship-based access control policies produce policies composed of relationship-based patterns that justify the input authorizations according to a given system graph. The correct functioning of a policy mining algorithm is typically tested based on experimental evaluations, in each of which the miner is presented with a set of authorizations and a system graph, and is expected to produce the corresponding ground truth policy. In this paper, we propose formal properties that must exist between the system graph and the ground truth policy in an evaluation test so that the miner is challenged to produce the exact ground truth policy. We show that failure to verify these properties in the experiment leads to inadequate evaluation, i.e., not truly testing whether the miner can handle the complexity of the ground truth policy. We also argue that following these properties would provide a computational advantage in the evaluations. We propose algorithms to identify and correct violations of these properties in system graphs. We also present our observations regarding these properties and their enforcement using a set of experimental studies.
学习具有未知值的基于属性和基于关系的访问控制策略
DOI: 10.1007/978-3-030-65610-2_2
发表时间: 2020
期刊: Proceedings of the 16th International Conference on Information Systems Security (ICISS
影响因子: --
作者:
Bui, Thang;Stoller, Scott D.
通讯作者: Stoller, Scott D.
基于属性感知关系的访问控制策略挖掘的可行性
DOI: 10.1007/978-3-030-81242-3_23
发表时间: 2021
期刊: Annual IFIP WG 11.3 Working Conference on Data and Applications Security and Privacy (DBSec
影响因子: --
作者:
Chakraborty, Shuvra;Sandhu, Ravi
通讯作者: Sandhu, Ravi
挖掘基于关系的访问控制策略的决策树学习方法
DOI: 10.1145/3381991.3395619
发表时间: 2020
期刊: Proceedings of the 25th ACM Symposium on Access Control Models and Technologies (SACMAT 2020
影响因子: --
作者:
Bui, Thang;Stoller, Scott D.
通讯作者: Stoller, Scott D.
ReBAC策略挖矿可行性的形式化分析
DOI: 10.1145/3422337.3447828
发表时间: 2021
期刊: 11th ACM Conference on Data and Application Security and Privacy (CODASPY
影响因子: --
作者:
Chakraborty, Shuvra;Sandhu, Ravi
通讯作者: Sandhu, Ravi
DOI: 10.1016/j.cose.2018.09.011
发表时间: 2019-01-01
影响因子: 5.6
作者:
Bui, Thang;Stoller, Scott D.;Li, Jiajie
通讯作者: Li, Jiajie