A Decision Tree Learning Approach for Mining Relationship-Based Access Control Policies

09/24/2019
by   Thang Bui, et al.
0

Relationship-based access control (ReBAC) provides a high level of expressiveness and flexibility that promotes security and information sharing, by allowing policies to be expressed in terms of chains of relationships between entities. ReBAC policy mining algorithms have the potential to significantly reduce the cost of migration from legacy access control systems to ReBAC, by partially automating the development of a ReBAC policy. This paper presents a new algorithm, based on decision trees, for mining ReBAC policies from access control lists (ACLs) and information about entities. The algorithm first learns an authorization policy in the form of a decision tree, and then extracts a set of candidate authorization rules from the decision tree. Next, it constructs the final mined policy by eliminating negative conditions from the candidate rules and then simplifying them. Compared to state-of-the-art ReBAC mining algorithms, DTRM is simpler, significantly faster, achieves similar policy quality, and can mine policies in a richer language.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
08/19/2020

Learning Attribute-Based and Relationship-Based Access Control Policies with Unknown Values

Attribute-Based Access Control (ABAC) and Relationship-based access cont...
research
03/18/2019

Efficient and Extensible Policy Mining for Relationship-Based Access Control

Relationship-based access control (ReBAC) is a flexible and expressive f...
research
11/13/2021

PAMMELA: Policy Administration Methodology using Machine Learning

In recent years, Attribute-Based Access Control (ABAC) has become quite ...
research
05/22/2018

Verifiable Reinforcement Learning via Policy Extraction

While deep reinforcement learning has successfully solved many challengi...
research
02/27/2016

Scalable Bayesian Rule Lists

We present an algorithm for building probabilistic rule lists that is tw...
research
04/20/2020

Sparse Oblique Decision Tree for Power System Security Rules Extraction and Embedding

Increasing the penetration of variable generation has a substantial effe...
research
06/06/2019

Blockwise Based Detection of Local Defects

Print quality is an important criterion for a printer's performance. The...

Please sign up or login with your details

Forgot password? Click here to reset