Learning Relationship-Based Access Control Policies from Black-Box Systems

被引:2
|
作者
Iyer, Padmavathi [1 ]
Masoumzadeh, Amirreza [1 ]
机构
[1] SUNY Albany, Albany, NY 12222 USA
基金
美国国家科学基金会;
关键词
Relationship-based access control; black box; model learning; formal analysis;
D O I
10.1145/3517121
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Access control policies are crucial in securing data in information systems. Unfortunately, often times, such policies are poorly documented, and gaps between their specification and implementation prevent the system users, and even its developers, from understanding the overall enforced policy of a system. To tackle this problem, we propose the first of its kind systematic approach for learning the enforced authorizations from a target system by interacting with and observing it as a black box. The black-box view of the target system provides the advantage of learning its overall access control policy without dealing with its internal design complexities. Furthermore, compared to the previous literature on policy mining and policy inference, we avoid exhaustive exploration of the authorization space by minimizing our observations. We focus on learning relationship-based access control (ReBAC) policy, and show how we can construct a deterministic finite automaton (DFA) to formally characterize such an enforced policy. We theoretically analyze our proposed learning approach by studying its termination, correctness, and complexity. Furthermore, we conduct extensive experimental analysis based on realistic application scenarios to establish its cost, quality of learning, and scalability in practice.
引用
收藏
页数:36
相关论文
共 50 条
  • [31] Black-Box vs. White-Box: Understanding Their Advantages and Weaknesses From a Practical Point of View
    Loyola-Gonzalez, Octavio
    IEEE ACCESS, 2019, 7 : 154096 - 154113
  • [32] Implementation of a Multifunction Black-box for Tower Crane Based on ARM and μCOS-II
    Yuan, Liyan
    Zhang, Guiqing
    Gao, Huanbing
    2008 7TH WORLD CONGRESS ON INTELLIGENT CONTROL AND AUTOMATION, VOLS 1-23, 2008, : 7681 - +
  • [33] ID-Based Traitor Tracing with Relaxed Black-Box Setting for Group-Based Applications
    Tseng, Yi-Fan
    Tso, Raylin
    Sun, Shi-Sheng
    Liu, Zi-Yuan
    Chen, You-Qian
    2024 19TH ASIA JOINT CONFERENCE ON INFORMATION SECURITY, ASIAJCIS 2024, 2024, : 33 - 39
  • [34] A Tensor-Based Volterra Series Black-Box Nonlinear System Identification And Simulation Framework
    Batselier, Kim
    Chen, Zhongming
    Liu, Haotian
    Wong, Ngai
    2016 IEEE/ACM INTERNATIONAL CONFERENCE ON COMPUTER-AIDED DESIGN (ICCAD), 2016,
  • [35] A discrete cosine transform-based query efficient attack on black-box object detectors
    Kuang, Xiaohui
    Gao, Xianfeng
    Wang, Lianfang
    Zhao, Gang
    Ke, Lishan
    Zhang, Quanxin
    INFORMATION SCIENCES, 2021, 546 : 596 - 607
  • [36] Black-Box Modeling of DC-DC Converters Based on Wavelet Convolutional Neural Networks
    Rojas-Duenas, Gabriel
    Riba, Jordi-Roger
    Moreno-Eguilaz, Manuel
    IEEE TRANSACTIONS ON INSTRUMENTATION AND MEASUREMENT, 2021, 70
  • [37] Black-Box Impedance Identification and Modeling for Time-Domain Transient Analysis of Power Electronics-Based Energy Conversion Systems
    Vahabzadeh, Taleb
    Ebrahimi, Seyyedmilad
    Jatskevich, Juri
    2024 23RD INTERNATIONAL SYMPOSIUM INFOTEH-JAHORINA, INFOTEH, 2024,
  • [38] Towards Automated Learning of Access Control Policies Enforced by Web Applications
    Iyer, Padmavathi
    Masoumzadeh, Amir
    PROCEEDINGS OF THE 28TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, SACMAT 2023, 2023, : 163 - 168
  • [39] Robust and Imperceptible Black-Box DNN Watermarking Based on Fourier Perturbation Analysis and Frequency Sensitivity Clustering
    Liu, Yong
    Wu, Hanzhou
    Zhang, Xinpeng
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (06) : 5766 - 5780
  • [40] Reputation Defender: Local Black-Box Adversarial Attack against Image-Translation-Based DeepFake
    Yang, Wang
    Zhao, Lingchen
    Ye, Dengpan
    2024 IEEE INTERNATIONAL CONFERENCE ON MULTIMEDIA AND EXPO, ICME 2024, 2024,