On the Feasibility of Attribute-Based Access Control Policy Mining

2019 IEEE 20th International Conference on Information Reuse and Integration for Data Science (IRI)(2019)

引用 8|浏览25
暂无评分
摘要
As the technology of attribute-based access control (ABAC) matures and begins to supplant earlier models such as role-based or discretionary access control, it becomes necessary to convert from already deployed access control systems to ABAC. Several variations of this general problem can be defined, some of which have been studied by researchers. In particular the ABAC policy mining problem assumes that attribute values for various entities such as users and objects in the system are given, in addition to the authorization state, from which the ABAC policy needs to be discovered. In this paper, we formalize the ABAC RuleSet Existence problem in this context and develop an algorithm and complexity analysis for its solution. We further introduce the notion of ABAC RuleSet Infeasibility Correction along with an algorithm for its solution.
更多
查看译文
关键词
Access Control, Attribute-Based Access Control, ABAC Policy Mining, ABAC Rule Existence Problem, Policy Mining
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要