Automated Generation and Update of Structured ABAC Policies

Research output: Chapter in Book/Report/Conference proceedingConference paperpeer-review

2 Citations (Scopus)

Abstract

We present a new access control policy generation algorithm that also offers a solution to the policy update problem. The algorithm generates structured attribute-based access control policies, more precisely, it generates a categorisation of principals and resources based on attribute values, together with rules that specify permissions for categories of principals on categories of resources. To facilitate the identification of user profiles associated with granted and denied requests, the algorithm generates both positive and negative categories (defining authorisations and prohibitions, respectively). The input for the algorithm is a set of access request logs together with attributes of entities in the system, and optionally an existing policy. If only logs are provided as input, the algorithm generates a policy that is consistent with the input logs (i.e., the mined policy includes the authorisations and prohibitions that occur in the logs). If instead the algorithm is used to update an existing policy, then it is sufficient to provide as input the policy and examples of authorisations and prohibitions that the updated version of the policy should include. To illustrate the algorithm, we describe its application to a public ICU health metric data set.

Original languageEnglish
Title of host publicationSaT-CPS 2024 - Proceedings of the 2024 ACM Workshop on Secure and Trustworthy Cyber-Physical Systems
PublisherAssociation for Computing Machinery, Inc
Pages31-40
Number of pages10
ISBN (Electronic)9798400705564
DOIs
Publication statusPublished - 21 Jun 2024
Event4th ACM Workshop on Secure and Trustworthy Cyber-Physical Systems, SaT-CPS 2024, held in conjunction with the 14th ACM Conference on Data and Application Security and Privacy, CODASPY 2024 - Porto, Portugal
Duration: 21 Jun 2024 → …

Publication series

NameSaT-CPS 2024 - Proceedings of the 2024 ACM Workshop on Secure and Trustworthy Cyber-Physical Systems

Conference

Conference4th ACM Workshop on Secure and Trustworthy Cyber-Physical Systems, SaT-CPS 2024, held in conjunction with the 14th ACM Conference on Data and Application Security and Privacy, CODASPY 2024
Country/TerritoryPortugal
CityPorto
Period21/06/2024 → …

Keywords

  • attribute-based access control
  • category-based access control
  • policy generation
  • policy update

Fingerprint

Dive into the research topics of 'Automated Generation and Update of Structured ABAC Policies'. Together they form a unique fingerprint.

Cite this