arrow
返回

Role Engineering via Prioritized Subset Enumeration

delete2010-07-01
delete41
PRE
AI
J
Jaideep Vaidya *
V
Vijayalakshmi Atluri
J
Janice Warner
Q
Qi Guo
DOI:10.1109/TDSC.2008.61delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Today, role-based access control (RBAC) has become a well-accepted paradigm for implementing access control because of its convenience and ease of administration. However, in order to realize the full benefits of the RBAC paradigm, one must first define the roles accurately. This task of defining roles and associating permissions with them, also known as role engineering, is typically accomplished either in a top-down or in a bottom-up manner. Under the top-down approach, a careful analysis of the business processes is done to first define job functions and then to specify appropriate roles from them. While this approach can help in defining roles more accurately, it is tedious and time consuming since it requires that the semantics of the business processes be well understood. Moreover, it ignores existing permissions within an organization and does not utilize them. On the other hand, under the bottom-up approach, existing permissions are used to derive roles from them. As a result, it may help automate the process of role definition. In this paper, we present an unsupervised approach, called RoleMiner, for mining roles from existing user-permission assignments. Since a role, when semantics are unavailable, is nothing but a set of permissions, the task of role mining is essentially that of clustering users having the same (or similar) permissions. However, unlike the traditional applications of data mining that ideally require identification of nonoverlapping clusters, roles will have overlapping permissions and thus permission sets that define roles should be allowed to overlap. It is this distinction from traditional clustering that makes the problem of role mining nontrivial. Our experiments with real and simulated data sets indicate that our role mining process is quite accurate and efficient. Since our role mining approach is based on subset enumeration, it is fairly robust to reasonable levels of noise.
Keyword:
Role-based access control
role engineering
data mining
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

IEEE Transactions on Dependable and Secure Computing 封面图
IEEE Transactions on Dependable and Secure Computing
IF:
7.5
论文数:
2.5K
被引数:
9.6K

机构

R
rutgers university system
学者数:
4.1W
论文数: 3.7W
被引数: 53
R
rutgers university new brunswick
学者数:
2.3W
论文数: 1.9W
被引数: 32
引用论文

引用论文

err分享
err收藏
Environmental Control of the In vivo Oligomerization of Nucleoid Protein H-NS
err2006-01-01
err0
PREAI
errStefano Stella; Maurizio Falconi; Matilde Lammi; Claudio O. Gualerzi; Cynthia L. Pon
err分享
err收藏
err分享
err收藏
err分享
err收藏
err分享
err收藏
学者 查看更多内容