Visual Role Mining: A Picture Is Worth a Thousand Roles

被引:26
作者
Colantonio, Alessandro [1 ]
Di Pietro, Roberto [2 ]
Ocello, Alberto [3 ]
Verde, Nino Vincenzo [2 ]
机构
[1] Bay31 GmbH, CH-6300 Zug, Switzerland
[2] Univ Roma Tre, I-00146 Rome, Italy
[3] Engiweb Secur, I-00185 Rome, Italy
关键词
Access controls; data and knowledge visualization; mining methods and algorithms; VISUALIZATION;
D O I
10.1109/TKDE.2011.37
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
This paper offers a new role engineering approach to Role-Based Access Control (RBAC), referred to as visual role mining. The key idea is to graphically represent user-permission assignments to enable quick analysis and elicitation of meaningful roles. First, we formally define the problem by introducing a metric for the quality of the visualization. Then, we prove that finding the best representation according to the defined metric is a NP-hard problem. In turn, we propose two algorithms: ADVISER and EXTRACT. The former is a heuristic used to best represent the user-permission assignments of a given set of roles. The latter is a fast probabilistic algorithm that, when used in conjunction with ADVISER, allows for a visual elicitation of roles even in absence of predefined roles. Besides being rooted in sound theory, our proposal is supported by extensive simulations run over real data. Results confirm the quality of the proposal and demonstrate its viability in supporting role engineering decisions.
引用
收藏
页码:1120 / 1133
页数:14
相关论文
共 29 条
[1]  
Chen CM, 2005, IEEE COMPUT GRAPH, V25, P12, DOI 10.1109/MCG.2005.91
[2]  
Chierichetti F, 2010, PROC APPL MATH, V135, P293
[3]  
Colantonio A, 2010, P 2010 ACM S APPL CO
[4]  
Colantonio A, 2008, PROCEEDINGS OF THE IFIP TC 11/ 23RD INTERNATIONAL INFORMATION SECURITY CONFERENCE, P333
[5]  
Colantonio A, 2010, IFIP ADV INF COMM TE, V330, P19
[6]   A new role mining framework to elicit business roles and to mitigate enterprise risk [J].
Colantonio, Alessandro ;
Di Pietro, Roberto ;
Ocello, Alberto ;
Verde, Nino Vincenzo .
DECISION SUPPORT SYSTEMS, 2011, 50 (04) :715-731
[7]   Taming role mining complexity in RBAC [J].
Colantonio, Alessandro ;
Di Pietro, Roberto ;
Ocello, Alberto ;
Verde, Nino Vincenzo .
COMPUTERS & SECURITY, 2010, 29 (05) :548-564
[8]  
Colantonio A, 2009, SACMAT'09: PROCEEDINGS OF THE 14TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, P85, DOI 10.1145/1542207.1542223
[9]  
Colantonio A, 2008, APPLIED COMPUTING 2008, VOLS 1-3, P2129
[10]  
Coyne E.J., 1995, Proc. ACM Workshop on Role-Based Access Control, P15