ACM Home Page
Please provide us with feedback. Feedback
An approach to evaluate policy similarity
Full text PdfPdf (247 KB)
Source
Symposium on Access Control Models and Technologies archive
Proceedings of the 12th ACM symposium on Access control models and technologies table of contents
Sophia Antipolis, France
SESSION: Policy management table of contents
Pages: 1 - 10  
Year of Publication: 2007
ISBN:978-1-59593-745-2
Authors
Dan Lin  Purdue University, West Lafayette, IN
Prathima Rao  Purdue University, West Lafayette, IN
Elisa Bertino  Purdue University, West Lafayette, IN
Jorge Lobo  IBM T.J. Watson Research Center, Yorktown, NY
Sponsors
ACM: Association for Computing Machinery
SIGSAC: ACM Special Interest Group on Security, Audit, and Control
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 8,   Downloads (12 Months): 132,   Citation Count: 3
Additional Information:

abstract   references   cited by   index terms   collaborative colleagues  

Tools and Actions: Request Permissions Request Permissions    Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/1266840.1266842
What is a DOI?

ABSTRACT

Recent collaborative applications and enterprises very often need to efficiently integrate their access control policies. An important step in policy integration is to analyze the similarity of policies. Existing approaches to policy similarity analysis are mainly based on logical reasoning and boolean function comparison. Such approaches are computationally expensive and do not scale well for large heterogeneous distributed environments (like Grid computing systems). In this paper, we propose a policy similarity measure as a filter phase for policy similarity analysis. This measure provides a lightweight approach to pre-compile a large amount of policies and only return the most similar policies for further evaluation. In the paper we formally define the measure, by taking into account both the case of categorical attributes and numeric attributes. Detailed algorithms are presented for the similarly computation. Results of our case study demonstrates the efficiency and practical value of our approach.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

 
1
2
3
 
4
M. Ehrig, P. Haase, M. Hefke, and N. Stojanovic. Similarity for ontologies - a comprehensive framework. In Proceedings of the 13th European Conference on Information Systems, Information Systems in a Rapidly Changing Economy (ECIS), 2005.
5
 
6
D. P. Guelev, M. Ryan, and P. Schobbens. Model-checking access control policies. In Proceedings of the 7th Information Security Conference (ISC), pages 219--230, 2004.
 
7
8
 
9
10
 
11
12
 
13
 
14
J. D. Moffett and M. S. Sloman. Policy conflict analysis in distributed system management. Journal of Organizational Computing, 1993.
 
15
T. Moses. Extensible access control markup language (xacml) version 1.0. Technical report, OASIS, 2003.
 
16
17
 
18
N. Zhang, M. Ryan, and D. P. Guelev. Evaluating access control policies through model checking. In Proceedings of the 8th Information Security Conference (ISC), pages 446--460, 2005.


Collaborative Colleagues:
Dan Lin: colleagues
Prathima Rao: colleagues
Elisa Bertino: colleagues
Jorge Lobo: colleagues