Skip to main navigation Skip to search Skip to main content

Learning Attribute-Based and Relationship-Based Access Control Policies with Unknown Values

  • Stony Brook University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

17 Scopus citations

Abstract

Attribute-Based Access Control (ABAC) and Relationship-based access control (ReBAC) provide a high level of expressiveness and flexibility that promote security and information sharing, by allowing policies to be expressed in terms of attributes of and chains of relationships between entities. Algorithms for learning ABAC and ReBAC policies from legacy access control information have the potential to significantly reduce the cost of migration to ABAC or ReBAC. This paper presents the first algorithms for mining ABAC and ReBAC policies from access control lists (ACLs) and incomplete information about entities, where the values of some attributes of some entities are unknown. We show that the core of this problem can be viewed as learning a concise three-valued logic formula from a set of labeled feature vectors containing unknowns, and we give the first algorithm (to the best of our knowledge) for that problem.

Original languageEnglish
Title of host publicationInformation Systems Security - 16th International Conference, ICISS 2020, Proceedings
EditorsSalil Kanhere, Vishwas T Patil, Shamik Sural, Manoj S Gaur
PublisherSpringer Science and Business Media Deutschland GmbH
Pages23-44
Number of pages22
ISBN (Print)9783030656096
DOIs
StatePublished - 2020
Event16th International Conference on Information Systems Security, ICISS 2020 - Jammu, India
Duration: Dec 16 2020Dec 20 2020

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume12553 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference16th International Conference on Information Systems Security, ICISS 2020
Country/TerritoryIndia
CityJammu
Period12/16/2012/20/20

Fingerprint

Dive into the research topics of 'Learning Attribute-Based and Relationship-Based Access Control Policies with Unknown Values'. Together they form a unique fingerprint.

Cite this