智能与分布计算实验室

Role Mining Based on Weights

出版社:
摘要内容:

Role mining from the existing permissions has been widelyapplied to aid the process of migrating to an RBAC sys-tem. While all permissions are treated evenly in previousapproaches, none of the work has employed the weights ofpermissions in role mining to our knowledge, thus providingthe motivation for this work. In this paper, we generalizethis to the case where permissions are given weights to re?ecttheir importance to the system. The weights can correspondto the property of operations, the sensitive degree of objects,and the attribute of users associated with permissions. Tocalculate the weight of permissions, we introduce the con-cept of similarity between both users and permissions, anduse a similarity matrix to reinforce the similarity betweenpermissions. Then we create a link between the reinforcedsimilarity and the weight of permissions. We further proposea weighted role mining algorithm to generate roles based onweights. Experiments on performance study prove the su-periority of the new algorithm.

关键词:
  • RBAC;role engineering;role mining;weight; similarity

会议:
  • 会议名称:The 15th ACM Symposium on Access Control Models and Technologies (SACMAT 2010)

  • 举办地点:Pittsburgh, PA,USA

  • 举办日期:June 2010

  • 页数:65-74

摘要内容:

Role mining from the existing permissions has been widely applied to aid the process of migrating to an RBAC sys- tem. While all permissions are treated evenly in previous approaches, none of the work has employed the weights of permissions in role mining to our knowledge, thus providing the motivation for this work. In this paper, we generalize this to the case where permissions are given weights to re?ect their importance to the system. The weights can correspond to the property of operations, the sensitive degree of objects, and the attribute of users associated with permissions. To calculate the weight of permissions, we introduce the con- cept of similarity between both users and permissions, and use a similarity matrix to reinforce the similarity between permissions. Then we create a link between the reinforced similarity and the weight of permissions. We further propose a weighted role mining algorithm to generate roles based on weights. Experiments on performance study prove the su- periority of the new algorithm.

关键词:
  • RBAC;role engineering;role mining;weight; similarity