Automatic Extraction of Access Control Policies from Natural Language Documents

被引:31
作者
Narouei, Masoud [1 ]
Takabi, Hassan [1 ]
Nielsen, Rodney [1 ]
机构
[1] Univ North Texas, Dept Comp Sciene & Engn, Denton, TX 76203 USA
关键词
Access control; Natural languages; Privacy; Semantics; Organizations; Tools; Permission; Access control policy; policy engineering; semantic role labeling; domain adaptation; semi-supervised learning; natural language processing; transfer learning;
D O I
10.1109/TDSC.2018.2818708
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
A fundamental management responsibility is securing information systems. Almost all applications that deal with safety, privacy, or defense include some form of access control. There are a plethora of access control models in the information security realm such as role-based access control and attribute-based access control. However, the initial development of access control policies (ACPs) can be very challenging. Most organizations have high-level requirement specifications that include a set of ACPs, which describe allowable operations of the system. It is time consuming and error-prone to manually sift through these documents and extract ACPs. In this paper, we propose a new framework towards extracting ACPs from unrestricted natural language documents using semantic role labeling (SRL). We were able to correctly identify ACP elements with an average $F_1$F1 score of 75 percent, which bested the previous work by 15 percent. Furthermore, as SRL tools are often trained on publicly available corpora such as Wall Street Journal, we investigated the idea of improving SRL performance using domain-related knowledge. We utilized domain adaptation and semi-supervised learning techniques and were able to improve the SRL performance by 2 percent using only a small amount of access control data.
引用
收藏
页码:506 / 517
页数:12
相关论文
共 40 条
[1]  
Ammar W., 2012, Technical Report CMU-LTI- 12-019
[2]  
[Anonymous], [No title captured]
[3]  
[Anonymous], CORR
[4]  
[Anonymous], [No title captured]
[5]  
[Anonymous], [No title captured]
[6]  
Baker C.F., 1998, P 36 ANN M ASS COMP, V1, P86, DOI [10.3115/980845.980860, DOI 10.3115/980845.980860]
[7]   Large Scale Application of Neural Network Based Semantic Role Labeling for Automated Relation Extraction from Biomedical Texts [J].
Barnickel, Thorsten ;
Weston, Jason ;
Collobert, Ronan ;
Mewes, Hans-Werner ;
Stuempflen, Volker .
PLOS ONE, 2009, 4 (07)
[8]  
Beckerle M., 2013, P 9 S US PRIV SEC SO
[9]  
Bjorkelund A, 2009, P 13 C COMP NAT LANG, P43
[10]  
Breaux T.D., 2009, Legal requirements acquisition for the specification of legally compliant information systems