首页> 外文会议>International conference on computer aided systems theory >Delta Analysis of Role-Based Access Control Models
【24h】

Delta Analysis of Role-Based Access Control Models

机译:基于角色的访问控制模型的增量分析

获取原文

摘要

Role-based Access Control (RBAC) is de facto standard for access control in Process-aware Information Systems (PAIS); it grants authorization to users based on roles (i.e. sets of permissions). So far, research has centered on the design and run time aspects of RBAC. An evaluation and verification of a RBAC system (e.g., to evaluate ex post which users acting in which roles were authorized to execute permissions) is still missing. In this paper, we propose delta analysis of RBAC models which compares a prescriptive RBAC model (i.e. how users are expected to work) with a RBAC model (i.e. how users have actually worked) derived from event logs. To do that, we transform RBAC models to graphs and analyze them for structural similarities and differences. Differences can indicate security violations such as unauthorized access. For future work, we plan to investigate semantic differences between RBAC models.
机译:基于角色的访问控制(RBAC)实际上是过程感知信息系统(PAIS)中访问控制的标准;它根据角色(即权限集)向用户授予授权。到目前为止,研究集中在RBAC的设计和运行时方面。仍然缺少对RBAC系统的评估和验证(例如,事后评估哪些用户在哪些角色中被授权执行权限的事后评估)。在本文中,我们提出了RBAC模型的增量分析,该分析将说明性RBAC模型(即预期用户的工作方式)与从事件日志中得出的RBAC模型(即用户实际的工作方式)进行了比较。为此,我们将RBAC模型转换为图形,并对其结构相似性和差异进行分析。差异可能表明存在违反安全性的情况,例如未经授权的访问。对于将来的工作,我们计划调查RBAC模型之间的语义差异。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号