Learning Relationship-Based Access Control Policies from Black-Box Systems

被引:2
|
作者
Iyer, Padmavathi [1 ]
Masoumzadeh, Amirreza [1 ]
机构
[1] SUNY Albany, Albany, NY 12222 USA
基金
美国国家科学基金会;
关键词
Relationship-based access control; black box; model learning; formal analysis;
D O I
10.1145/3517121
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Access control policies are crucial in securing data in information systems. Unfortunately, often times, such policies are poorly documented, and gaps between their specification and implementation prevent the system users, and even its developers, from understanding the overall enforced policy of a system. To tackle this problem, we propose the first of its kind systematic approach for learning the enforced authorizations from a target system by interacting with and observing it as a black box. The black-box view of the target system provides the advantage of learning its overall access control policy without dealing with its internal design complexities. Furthermore, compared to the previous literature on policy mining and policy inference, we avoid exhaustive exploration of the authorization space by minimizing our observations. We focus on learning relationship-based access control (ReBAC) policy, and show how we can construct a deterministic finite automaton (DFA) to formally characterize such an enforced policy. We theoretically analyze our proposed learning approach by studying its termination, correctness, and complexity. Furthermore, we conduct extensive experimental analysis based on realistic application scenarios to establish its cost, quality of learning, and scalability in practice.
引用
收藏
页数:36
相关论文
共 50 条
  • [1] Active Learning of Relationship-Based Access Control Policies
    Iyer, Padmavathi
    Masoumzadeh, Amirreza
    SACMAT'20: PROCEEDINGS OF THE 25TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, 2020, : 155 - 166
  • [2] Generalized Mining of Relationship-Based Access Control Policies in Evolving Systems
    Iyer, Padmavathi
    Masoumzadeh, Amirreza
    PROCEEDINGS OF THE 24TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES (SACMAT '19), 2019, : 135 - 140
  • [3] Security Analysis of Relationship-Based Access Control Policies
    Masoumzadeh, Amirreza
    PROCEEDINGS OF THE EIGHTH ACM CONFERENCE ON DATA AND APPLICATION SECURITY AND PRIVACY (CODASPY'18), 2018, : 186 - 195
  • [4] A Decision Tree Learning Approach for Mining Relationship-Based Access Control Policies
    Bui, Thang
    Stoller, Scott D.
    SACMAT'20: PROCEEDINGS OF THE 25TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, 2020, : 167 - 178
  • [5] A Datalog Framework for Modeling Relationship-based Access Control Policies
    Pasarella, Edelmira
    Lobo, Jorge
    PROCEEDINGS OF THE 22ND ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES (SACMAT'17), 2017, : 91 - 102
  • [6] Greedy and evolutionary algorithms for mining relationship-based access control policies
    Bui, Thang
    Stoller, Scott D.
    Li, Jiajie
    COMPUTERS & SECURITY, 2019, 80 : 317 - 333
  • [7] Attributes Aware Relationship-based Access Control for Smart IoT Systems
    Praharaj, Lopamudra
    Ameer, Safwa
    Gupta, Maanak
    Sandhu, Ravi
    2022 IEEE 8TH INTERNATIONAL CONFERENCE ON COLLABORATION AND INTERNET COMPUTING, CIC, 2022, : 72 - 81
  • [8] Efficient and Extensible Policy Mining for Relationship-Based Access Control
    Bui, Thang
    Stoller, Scott D.
    Le, Hieu
    PROCEEDINGS OF THE 24TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES (SACMAT '19), 2019, : 161 - 172
  • [9] Effective Evaluation of Relationship-Based Access Control Policy Mining
    Iyer, Padmavathi
    Masoumzadeh, Amirreza
    PROCEEDINGS OF THE 27TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, SACMAT 2022, 2022, : 127 - 138
  • [10] Poster: A Flexible Relationship-Based Access Control Policy Generator
    Clark, Stanley
    Yakovets, Nikolay
    Fletcher, George H. L.
    Zannone, Nicola
    PROCEEDINGS OF THE 27TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, SACMAT 2022, 2022, : 263 - 265