TY - GEN
T1 - Mining relationship-based access control policies
AU - Bui, Thang
AU - Stoller, Scott D.
AU - Li, Jiajie
N1 - Publisher Copyright:
© 2017 Association for Computing Machinery.
PY - 2017/6/7
Y1 - 2017/6/7
N2 - Relationship-based access control (ReBAC) provides a high level of expressiveness and flexibility that promotes security and information sharing. We formulate ReBAC as an object-oriented extension of Attribute-based access control (ABAC) in which relationships are expressed using fields that refer to other objects, and path expressions are used to follow chains of relationships between objects. ReBAC policy mining algorithms have potential to significantly reduce the cost of migration from legacy access control systems to ReBAC, by partially automating the development of a ReBAC policy from an existing access control policy and Attribute data. This paper presents an algorithm for mining ReBAC policies from access control lists (ACLs) and Attribute data represented as an object model, and an evaluation of the algorithm on four sample policies and two large case studies. Our algorithm can be adapted to mine ReBAC policies from access logs and object models. It is the first algorithm for these problems.
AB - Relationship-based access control (ReBAC) provides a high level of expressiveness and flexibility that promotes security and information sharing. We formulate ReBAC as an object-oriented extension of Attribute-based access control (ABAC) in which relationships are expressed using fields that refer to other objects, and path expressions are used to follow chains of relationships between objects. ReBAC policy mining algorithms have potential to significantly reduce the cost of migration from legacy access control systems to ReBAC, by partially automating the development of a ReBAC policy from an existing access control policy and Attribute data. This paper presents an algorithm for mining ReBAC policies from access control lists (ACLs) and Attribute data represented as an object model, and an evaluation of the algorithm on four sample policies and two large case studies. Our algorithm can be adapted to mine ReBAC policies from access logs and object models. It is the first algorithm for these problems.
UR - https://www.scopus.com/pages/publications/85025438081
U2 - 10.1145/3078861.3078878
DO - 10.1145/3078861.3078878
M3 - Conference contribution
AN - SCOPUS:85025438081
T3 - Proceedings of ACM Symposium on Access Control Models and Technologies, SACMAT
SP - 239
EP - 246
BT - SACMAT 2017 - Proceedings of the 22nd ACM Symposium on Access Control Models and Technologies
PB - Association for Computing Machinery
T2 - 22nd ACM Symposium on Access Control Models and Technologies, SACMAT 2017
Y2 - 21 June 2017 through 23 June 2017
ER -