首页> 外文会议>International conference on computer aided systems theory >Delta Analysis of Role-Based Access Control Models
【24h】

Delta Analysis of Role-Based Access Control Models

机译:基于角色的访问控制模型的三角洲分析

获取原文

摘要

Role-based Access Control (RBAC) is de facto standard for access control in Process-aware Information Systems (PAIS); it grants authorization to users based on roles (i.e. sets of permissions). So far, research has centered on the design and run time aspects of RBAC. An evaluation and verification of a RBAC system (e.g., to evaluate ex post which users acting in which roles were authorized to execute permissions) is still missing. In this paper, we propose delta analysis of RBAC models which compares a prescriptive RBAC model (i.e. how users are expected to work) with a RBAC model (i.e. how users have actually worked) derived from event logs. To do that, we transform RBAC models to graphs and analyze them for structural similarities and differences. Differences can indicate security violations such as unauthorized access. For future work, we plan to investigate semantic differences between RBAC models.
机译:基于角色的访问控制(RBAC)是处理感知信息系统(PAI)中的访问控制的事实标准;它根据角色授予用户授权(即权限组)。到目前为止,研究以RBAC的设计和运行时间方面为中心。 RBAC系统的评估与验证(例如,评估EX POST,其中用户的作用被授权执行权限)仍然缺失。在本文中,我们提出了RBAC模型的Delta分析,该模型与RBAC模型(即用户预期的用户预期工作)进行了比较的RBAC模型(即,用户实际上有效)派生自Event日志。为此,我们将RBAC模型转换为图形并分析它们的结构性相似和差异。差异可以指示安全违规,例如未经授权的访问权限。对于未来的工作,我们计划调查RBAC模型之间的语义差异。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号