DocumentCode :
1725803
Title :
Towards Automated Assistance for Mined Roles Analysis in Role Mining Applications
Author :
Hachana, Safaà ; Cuppens, Frédéric ; Cuppens-Boulahia, Nora ; Garcia-Alfaro, Joaquin
Author_Institution :
Swid Web Performance Service, Rennes, France
fYear :
2012
Firstpage :
123
Lastpage :
132
Abstract :
The use of role engineering has grown in importance with the expansion of highly abstracted access control frameworks in organizations. In particular, the use of role mining techniques for the discovery of roles from previously deployed authorizations has facilitated the configuration of such frameworks. However, the literature lacks from a clear basis for appraising and leveraging the learning outcomes of the role mining process. In this paper, we provide such a formal basis. We compare sets of roles by projecting roles from one set into the other set. This approach allows to measure how comparable the two configurations of roles are, and to interpret each role. We formally define the problem of comparing sets of roles, and prove that the problem is NP-complete. Then, we propose an algorithm to map the inherent relation among the sets based on algebraic expressions. We demonstrate the correctness and completeness of our solution, and investigate some further issues that may benefit from our approach, such as detection of unhandled perturbations or source misconfiguration.
Keywords :
algebra; authorisation; computational complexity; data mining; learning (artificial intelligence); NP-complete problem; abstracted access control frameworks; algebraic expressions; automated assistance; learning outcomes; mined roles analysis; role discovery; role engineering; role mining applications; role projection; source misconfiguration; unhandled perturbation detection; Algorithm design and analysis; Authorization; Data mining; Optimization; Organizations; Access Control; Boolean Logic; IT Security; Role Mining;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Availability, Reliability and Security (ARES), 2012 Seventh International Conference on
Conference_Location :
Prague
Print_ISBN :
978-1-4673-2244-7
Type :
conf
DOI :
10.1109/ARES.2012.61
Filename :
6329172
Link To Document :
بازگشت