论文标题

自动属性的访问控制策略从访问日志提取

An Automatic Attribute Based Access Control Policy Extraction from Access Logs

论文作者

Karimi, Leila, Aldairi, Maryam, Joshi, James, Abdelhakim, Mai

论文摘要

随着计算和信息技术方面的快速进步,传统的访问控制模型在捕获新兴应用程序的细粒度和表达安全要求方面变得不足。基于属性的访问控制(ABAC)模型为满足复杂和动态系统的授权需求提供了一种更灵活的方法。尽管组织有兴趣采用更新的授权模型,但迁移到此类模型构成了重大挑战。许多大规模企业需要向其用户群体授予授权,这些用户群体潜在地分布在不同的和异质的计算环境中。这些计算环境中的每一个都可能具有其自己的访问控制模型。整个组织的单个政策框架的手动开发非常乏味,昂贵且容易出错。 在本文中,我们提出了一种从系统的访问日志中自动学习ABAC策略规则的方法,以简化策略开发过程。所提出的方法采用了一种基于学习的算法来检测访问日志中的模式并从这些模式中提取ABAC授权规则。此外,我们还提出了两种政策改进算法,包括规则修剪和政策改进算法,以生成更高质量的开采政策。最后,我们实施了提出的方法的原型,以证明其可行性。

With the rapid advances in computing and information technologies, traditional access control models have become inadequate in terms of capturing fine-grained, and expressive security requirements of newly emerging applications. An attribute-based access control (ABAC) model provides a more flexible approach for addressing the authorization needs of complex and dynamic systems. While organizations are interested in employing newer authorization models, migrating to such models pose as a significant challenge. Many large-scale businesses need to grant authorization to their user populations that are potentially distributed across disparate and heterogeneous computing environments. Each of these computing environments may have its own access control model. The manual development of a single policy framework for an entire organization is tedious, costly, and error-prone. In this paper, we present a methodology for automatically learning ABAC policy rules from access logs of a system to simplify the policy development process. The proposed approach employs an unsupervised learning-based algorithm for detecting patterns in access logs and extracting ABAC authorization rules from these patterns. In addition, we present two policy improvement algorithms, including rule pruning and policy refinement algorithms to generate a higher quality mined policy. Finally, we implement a prototype of the proposed approach to demonstrate its feasibility.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源