TY - GEN
T1 - Efficient and extensible policy mining for relationship-based access control
AU - Bui, Thang
AU - Stoller, Scott D.
AU - Le, Hieu
N1 - Publisher Copyright:
© 2019 Association for Computing Machinery.
PY - 2019/5/28
Y1 - 2019/5/28
N2 - Relationship-based access control (ReBAC) is a flexible and expressive framework that allows policies to be expressed in terms of chains of relationship between entities as well as attributes of entities. ReBAC policy mining algorithms have a potential to significantly reduce the cost of migration from legacy access control systems to ReBAC, by partially automating the development of a ReBAC policy. Existing ReBAC policy mining algorithms support a policy language with a limited set of operators; this limits their applicability. This paper presents a ReBAC policy mining algorithm designed to be both (1) easily extensible (to support additional policy language features) and (2) scalable. The algorithm is based on Bui et al.'s evolutionary algorithm for ReBAC policy mining algorithm. First, we simplify their algorithm, in order to make it easier to extend and provide a methodology that extends it to handle new policy language features. However, extending the policy language increases the search space of candidate policies explored by the evolutionary algorithm, thus causes longer running time and/or worse results. To address the problem, we enhance the algorithm with a feature selection phase. The enhancement utilizes a neural network to identify useful features. We use the result of feature selection to reduce the evolutionary algorithm's search space. The new algorithm is easy to extend and, as shown by our experiments, is more efficient and produces better policies.
AB - Relationship-based access control (ReBAC) is a flexible and expressive framework that allows policies to be expressed in terms of chains of relationship between entities as well as attributes of entities. ReBAC policy mining algorithms have a potential to significantly reduce the cost of migration from legacy access control systems to ReBAC, by partially automating the development of a ReBAC policy. Existing ReBAC policy mining algorithms support a policy language with a limited set of operators; this limits their applicability. This paper presents a ReBAC policy mining algorithm designed to be both (1) easily extensible (to support additional policy language features) and (2) scalable. The algorithm is based on Bui et al.'s evolutionary algorithm for ReBAC policy mining algorithm. First, we simplify their algorithm, in order to make it easier to extend and provide a methodology that extends it to handle new policy language features. However, extending the policy language increases the search space of candidate policies explored by the evolutionary algorithm, thus causes longer running time and/or worse results. To address the problem, we enhance the algorithm with a feature selection phase. The enhancement utilizes a neural network to identify useful features. We use the result of feature selection to reduce the evolutionary algorithm's search space. The new algorithm is easy to extend and, as shown by our experiments, is more efficient and produces better policies.
KW - Attribute-based access control
KW - Feature selection
KW - Relationship-based access control
KW - Security policy mining
UR - https://www.scopus.com/pages/publications/85067197403
U2 - 10.1145/3322431.3325106
DO - 10.1145/3322431.3325106
M3 - Conference contribution
AN - SCOPUS:85067197403
T3 - Proceedings of ACM Symposium on Access Control Models and Technologies, SACMAT
SP - 161
EP - 172
BT - SACMAT 2019 - Proceedings of the 24th ACM Symposium on Access Control Models and Technologies
PB - Association for Computing Machinery
T2 - 24th ACM Symposium on Access Control Models and Technologies, SACMAT 2019
Y2 - 3 June 2019 through 6 June 2019
ER -