Skip to main navigation Skip to search Skip to main content

Mining relationship-based access control policies

  • Stony Brook University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

22 Scopus citations

Abstract

Relationship-based access control (ReBAC) provides a high level of expressiveness and flexibility that promotes security and information sharing. We formulate ReBAC as an object-oriented extension of Attribute-based access control (ABAC) in which relationships are expressed using fields that refer to other objects, and path expressions are used to follow chains of relationships between objects. ReBAC policy mining algorithms have potential to significantly reduce the cost of migration from legacy access control systems to ReBAC, by partially automating the development of a ReBAC policy from an existing access control policy and Attribute data. This paper presents an algorithm for mining ReBAC policies from access control lists (ACLs) and Attribute data represented as an object model, and an evaluation of the algorithm on four sample policies and two large case studies. Our algorithm can be adapted to mine ReBAC policies from access logs and object models. It is the first algorithm for these problems.

Original languageEnglish
Title of host publicationSACMAT 2017 - Proceedings of the 22nd ACM Symposium on Access Control Models and Technologies
PublisherAssociation for Computing Machinery
Pages239-246
Number of pages8
ISBN (Electronic)9781450347020
DOIs
StatePublished - Jun 7 2017
Event22nd ACM Symposium on Access Control Models and Technologies, SACMAT 2017 - Indianapolis, United States
Duration: Jun 21 2017Jun 23 2017

Publication series

NameProceedings of ACM Symposium on Access Control Models and Technologies, SACMAT
VolumePart F128644

Conference

Conference22nd ACM Symposium on Access Control Models and Technologies, SACMAT 2017
Country/TerritoryUnited States
CityIndianapolis
Period06/21/1706/23/17

Fingerprint

Dive into the research topics of 'Mining relationship-based access control policies'. Together they form a unique fingerprint.

Cite this