Learning Relationship-Based Access Control Policies from Black-Box Systems

被引:2
|
作者
Iyer, Padmavathi [1 ]
Masoumzadeh, Amirreza [1 ]
机构
[1] SUNY Albany, Albany, NY 12222 USA
基金
美国国家科学基金会;
关键词
Relationship-based access control; black box; model learning; formal analysis;
D O I
10.1145/3517121
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Access control policies are crucial in securing data in information systems. Unfortunately, often times, such policies are poorly documented, and gaps between their specification and implementation prevent the system users, and even its developers, from understanding the overall enforced policy of a system. To tackle this problem, we propose the first of its kind systematic approach for learning the enforced authorizations from a target system by interacting with and observing it as a black box. The black-box view of the target system provides the advantage of learning its overall access control policy without dealing with its internal design complexities. Furthermore, compared to the previous literature on policy mining and policy inference, we avoid exhaustive exploration of the authorization space by minimizing our observations. We focus on learning relationship-based access control (ReBAC) policy, and show how we can construct a deterministic finite automaton (DFA) to formally characterize such an enforced policy. We theoretically analyze our proposed learning approach by studying its termination, correctness, and complexity. Furthermore, we conduct extensive experimental analysis based on realistic application scenarios to establish its cost, quality of learning, and scalability in practice.
引用
收藏
页数:36
相关论文
共 50 条
  • [41] An energy-saving oriented air balancing method for demand controlled ventilation systems with branch and black-box model
    Cui, Can
    Zhang, Xin
    Cai, Wenjian
    APPLIED ENERGY, 2020, 264
  • [42] Pseudo-Siamese Network based Timbre-reserved Black-box Adversarial Attack in Speaker Identification
    Wang, Qing
    Yao, Jixun
    Wang, Ziqian
    Guo, Pengcheng
    Xie, Lei
    INTERSPEECH 2023, 2023, : 3994 - 3998
  • [43] From White to Black-Box Models: A Review of Simulation Tools for Building Energy Management and Their Application in Consulting Practices
    Shahcheraghian, Amir
    Madani, Hatef
    Ilinca, Adrian
    ENERGIES, 2024, 17 (02)
  • [44] Validation of a black-box heat pump simulation model by means of field test results from five installations
    Ruschenburg, Joern
    Cutic, Tomislav
    Herkel, Sebastian
    ENERGY AND BUILDINGS, 2014, 84 : 506 - 515
  • [45] White-Box and Black-Box Reliability Modeling Framework: Integration Through Analytical Model and User Profile Validation via Deep Learning - A Practitioner's Approach
    Mohan, K. Krishna
    Shaik, Harun Ul Rasheed
    Srividya, A.
    Verma, Ajit Kumar
    INTERNATIONAL JOURNAL OF RELIABILITY QUALITY AND SAFETY ENGINEERING, 2021, 28 (06)
  • [46] A Black-Box Construction of a CCA2 Encryption Scheme from a Plaintext Aware (sPA1) Encryption Scheme
    Dachman-Soled, Dana
    PUBLIC-KEY CRYPTOGRAPHY - PKC 2014, 2014, 8383 : 37 - 55
  • [47] Interoperability of Relationship- and Role-Based Access Control
    Rizvi, Syed Zain R.
    Fong, Philip W. L.
    CODASPY'16: PROCEEDINGS OF THE SIXTH ACM CONFERENCE ON DATA AND APPLICATION SECURITY AND PRIVACY, 2016, : 231 - 242
  • [48] Black box-assisted fine-grained hierarchical access control scheme for epidemiological survey data
    Liu, Xueyan
    Sun, Ruirui
    Li, Linpeng
    Li, Wenjing
    Liu, Tao
    KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2023, 17 (09): : 2550 - 2572
  • [50] The Evolution of the Performance Model from Black Box to the Logic Model Through Systems Thinking
    Williams, Daniel
    INTERNATIONAL JOURNAL OF PUBLIC ADMINISTRATION, 2014, 37 (13) : 932 - 944