|
ABSTRACT
With continuously growing numbers of applications, enterprises face the problem of efficiently managing the assignment of access permissions to their users. On the one hand, security demands a tight regime on permissions; on the other hand, users need permissions to perform their tasks. Role-based access control (RBAC) has proven to be a solution to this problem but relies on a well-defined set of role definitions, a role concept for the enterprise in question. The definition of a role concept (role engineering) is a difficult task traditionally performed via interviews and workshops. However, often users already have the permissions that they need to do their jobs, and roles can be derived from these permission assignments using data mining technology, thus giving the process of role concept definition a head-start.In this paper, we present the ORCA role mining tool and its algorithm. The algorithm performs a cluster analysis on permission assignments to build a hierarchy of permission clusters and presents the results to the user in graphical form. It allows the user to interactively add expert knowledge to guide the clustering algorithm. The tool provides valuable insights into the permission structures of an enterprise and delivers an initial role hierarchy for the definition of an enterprise role concept using a bottom-up approach.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
ACM. Proceedings of the 3rd ACM Workshop on Role-Based Access Control (RBAC 1998). ACM Press, 1998.
|
| |
2
|
ACM. Proceedings of the 4th ACM workshop on Role-Based Access Control (RBAC 1999). ACM Press, 1999.
|
| |
3
|
ACM. Proceedings of the 5th ACM workshop on Role-Based Access Control (RBAC 2000). ACM Press, 2000.
|
| |
4
|
Information Technology -- Role Based Access Control. Number ANSI/INCITS 359-2004. InterNational Committee for Information Technology Standards, 2004.
|
 |
5
|
|
| |
6
|
|
| |
7
|
D. Ferraiolo and R. Kuhn. Role-based access controls. In 15th NIST-NCSC National Computer Security Conference, pages 554--563, 1992.
|
| |
8
|
U. Grimmer and H. Hinrichs. A methodological approach to data quality management supported by data mining. In E. M. Pierce and R. Katz-Haas, editors, 6th Conference on Information Quality (IQ 2001), pages 217--232. MIT, 2001.
|
| |
9
|
|
| |
10
|
|
| |
11
|
|
 |
12
|
|
 |
13
|
|
 |
14
|
|
| |
15
|
|
 |
16
|
|
 |
17
|
|
 |
18
|
|
| |
19
|
R. Rymon. SE-trees outperform decision trees in noisy domains. In Proceedings of the Second International Conference on Knowledge Discovery and Data Mining (KDD-96), pages 331--334. AAAI Press, 1996.
|
| |
20
|
R. Rymon. Sage -- Enabling Role-Based User Management. Presentation slides, Eurekify, Dec. 2002.
|
 |
21
|
|
 |
22
|
Ravi Sandhu , Venkata Bhamidipati , Edward Coyne , Srinivas Ganta , Charles Youman, The ARBAC97 model for role-based administration of roles: preliminary description and outline, Proceedings of the second ACM workshop on Role-based access control, p.41-50, November 06-07, 1997, Fairfax, Virginia, United States
[doi> 10.1145/266741.266752]
|
| |
23
|
|
| |
24
|
G. Schimpf. Role-engineering: Critical success factors for enterprise security administration. Position paper for {17}Dec. 2000.
|
| |
25
|
M. Sel. RBAC & Role Mining. Technical report, COSIC, 2004.
|
CITED BY 13
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Alina Ene , William Horne , Nikola Milosavljevic , Prasad Rao , Robert Schreiber , Robert E. Tarjan, Fast exact and heuristic methods for role minimization problems, Proceedings of the 13th ACM symposium on Access control models and technologies, June 11-13, 2008, Estes Park, CO, USA
|
|
|
|
|
|
Jaideep Vaidya , Vijayalakshmi Atluri , Qi Guo , Nabil Adam, Migrating to optimal RBAC with minimal perturbation, Proceedings of the 13th ACM symposium on Access control models and technologies, June 11-13, 2008, Estes Park, CO, USA
|
|
|
Ian Molloy , Hong Chen , Tiancheng Li , Qihua Wang , Ninghui Li , Elisa Bertino , Seraphin Calo , Jorge Lobo, Mining roles with semantic meanings, Proceedings of the 13th ACM symposium on Access control models and technologies, June 11-13, 2008, Estes Park, CO, USA
|
|
|
|
|
|
|
|
|
Ian Molloy , Ninghui Li , Tiancheng Li , Ziqing Mao , Qihua Wang , Jorge Lobo, Evaluating role mining algorithms, Proceedings of the 14th ACM symposium on Access control models and technologies, June 03-05, 2009, Stresa, Italy
|
|
|
|
|