Active learning of relationship-based access control policies

16Citations
Citations of this article
16Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Understanding access control policies is essential in understanding the security behavior of systems. However, often times, a complete and accurate specification of the enforced access control policy in a system is not available. In fact, scale and complexity of a system, or unavailability of its source code, may prevent users and even its developers from having access to such accurate specification. In this paper, we propose a novel, systematic approach for learning access control policies where target systems are treated as black boxes. In particular, we show how we can construct a deterministic finite automaton (DFA) characterizing the relationship-based access control (ReBAC) policy of a system by interacting with its access control engine using minimal number of access requests. Our experiments on realistic application scenarios and their promising results demonstrate the feasibility, scalability and efficiency of our learning approach.

Cite

CITATION STYLE

APA

Iyer, P., & Masoumzadeh, A. (2020). Active learning of relationship-based access control policies. In Proceedings of ACM Symposium on Access Control Models and Technologies, SACMAT (pp. 155–166). Association for Computing Machinery. https://doi.org/10.1145/3381991.3395614

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free