Learning Relationship-Based Access Control Policies from Black-Box Systems

被引:2
|
作者
Iyer, Padmavathi [1 ]
Masoumzadeh, Amirreza [1 ]
机构
[1] SUNY Albany, Albany, NY 12222 USA
基金
美国国家科学基金会;
关键词
Relationship-based access control; black box; model learning; formal analysis;
D O I
10.1145/3517121
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Access control policies are crucial in securing data in information systems. Unfortunately, often times, such policies are poorly documented, and gaps between their specification and implementation prevent the system users, and even its developers, from understanding the overall enforced policy of a system. To tackle this problem, we propose the first of its kind systematic approach for learning the enforced authorizations from a target system by interacting with and observing it as a black box. The black-box view of the target system provides the advantage of learning its overall access control policy without dealing with its internal design complexities. Furthermore, compared to the previous literature on policy mining and policy inference, we avoid exhaustive exploration of the authorization space by minimizing our observations. We focus on learning relationship-based access control (ReBAC) policy, and show how we can construct a deterministic finite automaton (DFA) to formally characterize such an enforced policy. We theoretically analyze our proposed learning approach by studying its termination, correctness, and complexity. Furthermore, we conduct extensive experimental analysis based on realistic application scenarios to establish its cost, quality of learning, and scalability in practice.
引用
收藏
页数:36
相关论文
共 50 条
  • [31] Black-box electronics and passive learning
    Hess, Karl
    PHYSICS TODAY, 2014, 67 (02) : 11 - 12
  • [32] Active Learning in Black-Box Settings
    Rubens, Neil
    Sheinman, Vera
    Tomioka, Ryota
    Sugiyama, Masashi
    AUSTRIAN JOURNAL OF STATISTICS, 2011, 40 (1-2) : 125 - 135
  • [33] Relationship-based access control: More than a social network access control model
    Lobo, Jorge
    WILEY INTERDISCIPLINARY REVIEWS-DATA MINING AND KNOWLEDGE DISCOVERY, 2019, 9 (02)
  • [34] Control of Black-Box Embedded Systems by Integrating Automaton Learning and Supervisory Control Theory of Discrete-Event Systems
    Zhang, Huimin
    Feng, Lei
    Li, Zhiwu
    IEEE TRANSACTIONS ON AUTOMATION SCIENCE AND ENGINEERING, 2020, 17 (01) : 361 - 374
  • [35] Probabilistic verification for "black-box" systems
    Younes, HLS
    COMPUTER AIDED VERIFICATION< PROCEEDINGS, 2005, 3576 : 253 - 265
  • [36] NATURAL SYSTEMS VS THE BLACK-BOX
    LOGSDON, G
    BIOCYCLE, 1989, 30 (06) : 68 - 69
  • [37] Classifying and Comparing Attribute-Based and Relationship-Based Access Control
    Ahmed, Tahmina
    Sandhu, Ravi
    Park, Jaehong
    PROCEEDINGS OF THE SEVENTH ACM CONFERENCE ON DATA AND APPLICATION SECURITY AND PRIVACY (CODASPY'17), 2017, : 59 - 70
  • [38] Efficient and Extensible Policy Mining for Relationship-Based Access Control
    Bui, Thang
    Stoller, Scott D.
    Le, Hieu
    PROCEEDINGS OF THE 24TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES (SACMAT '19), 2019, : 161 - 172
  • [39] Semantic Representation of RTBAC: Relationship-Based Access Control Model
    Chae, Song-hwa
    Kim, Wonil
    ADVANCES IN WEB AND NETWORK TECHNOLOGIES, AND INFORMATION MANAGEMENT, PROCEEDINGS, 2007, 4537 : 554 - +
  • [40] EMS SYSTEMS - OPENING THE BLACK-BOX
    MAIO, RF
    ANNALS OF EMERGENCY MEDICINE, 1993, 22 (04) : 730 - 731