Attribute-Based Mining Process for the Organization-Based Access Control Model

Ahmad Samer Wazan, Gregory Blanc, Herve Debar, Joaquin Garcia-Alfaro
<span title="">2013</span> <i title="IEEE"> <a target="_blank" rel="noopener" href="" style="color: black;">2013 12th IEEE International Conference on Trust, Security and Privacy in Computing and Communications</a> </i> &nbsp;
Since the late 60's, different security access control models have been proposed. Their rationale is to conceive high level abstract concepts that permit to manage the security policies of organizations efficiently. However, enforcing these models is not a straightforward task, especially when they do not consider the reality of organizations which may have ad-hoc security policies already deployed. Another issue is the vagueness of their abstract concepts. We propose to bridge the gap between
the theory of access control models and the reality of organizations by defining an attribute-based mining process that deduce the abstract concepts starting from the attribute level. Additionaly, the attributes allow us to semantically enrich the obtained results. We have selected the Organization-Based Access Control (OrBAC) model as the abstraction objective of our study.
<span class="external-identifiers"> <a target="_blank" rel="external noopener noreferrer" href="">doi:10.1109/trustcom.2013.53</a> <a target="_blank" rel="external noopener" href="">dblp:conf/trustcom/WazanBDG13</a> <a target="_blank" rel="external noopener" href="">fatcat:ufefm5rkujebho3gckq2gacgji</a> </span>
