2019/09/24 by Thang Bui, Bui, Thang, Scott D. Stoller +1 · 1 citation
Social Sciences · Computer Science · #Access Control and Trust #Internet Traffic Analysis and Secure E-voting
paper · pdf · doi:10.48550/arxiv.1909.12095
Relationship-based access control (ReBAC) provides a high level of\nexpressiveness and flexibility that promotes security and information sharing,\nby allowing policies to be expressed in terms of chains of relationships\nbetween entities. ReBAC policy mining algorithms have the potential to\nsignificantly reduce the cost of migration from legacy access control systems\nto ReBAC, by partially automating the development of a ReBAC policy.\n This paper presents new algorithms, called DTRM (Decision Tree ReBAC Miner)\nand DTRM-, based on decision trees, for mining ReBAC policies from access\ncontrol lists (ACLs) and information about entities. Compared to\nstate-of-the-art ReBAC mining algorithms, our algorithms are significantly\nfaster, achieve comparable policy quality, and can mine policies in a richer\nlanguage.\n