Skip to main navigation Skip to search Skip to main content

Mining hierarchical temporal roles with multiple metrics

  • Stony Brook University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

7 Scopus citations

Abstract

Temporal role-based access control (TRBAC) extends rolebased access control to limit the times at which roles are enabled. This paper presents a new algorithm for mining high-quality TRBAC policies from timed ACLs (i.e., ACLs with time limits in the entries) and optionally user attribute information. Such algorithms have potential to significantly reduce the cost of migration from timed ACLs to TRBAC. The algorithm is parameterized by the policy quality metric.We consider multiple quality metrics, including number of roles, weighted structural complexity (a generalization of policy size), and (when user attribute information is available) interpretability, i.e., how well role membership can be characterized in terms of user attributes. Ours is the first TRBAC policy mining algorithm that produces hierarchical policies, and the first that optimizes weighted structural complexity or interpretability. In experiments with datasets based on real-world ACL policies, our algorithm is more effective than previous algorithms at their goal of minimizing the number of roles.

Original languageEnglish
Title of host publicationData and Applications Security and Privacy - 30th Annual IFIP WG 11.3 Conference, DBSec 2016, Proceedings
EditorsSilvio Ranise, Vipin Swarup
PublisherSpringer Verlag
Pages79-95
Number of pages17
ISBN (Print)9783319414829
DOIs
StatePublished - 2016
Event30th IFIP WG 11.3 Conference on Data and Applications Security, DBSec 2016 - Trento, Italy
Duration: Jul 18 2016Jul 20 2016

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume9766
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference30th IFIP WG 11.3 Conference on Data and Applications Security, DBSec 2016
Country/TerritoryItaly
CityTrento
Period07/18/1607/20/16

Fingerprint

Dive into the research topics of 'Mining hierarchical temporal roles with multiple metrics'. Together they form a unique fingerprint.

Cite this