Delta Analysis of Role-Based Access Control Models
Role-based Access Control (RBAC) is de facto standard for access control in Process-aware Information Systems (PAIS); it grants authorization to users based on roles (i.e. sets of permissions). So far, research has centered on the design and run time aspects of RBAC. An evaluation and verification of a RBAC system (e.g., to evaluate ex post which users acting in which roles were authorized to execute permissions) is still missing. In this paper, we propose delta analysis of RBAC models which compares a prescriptive RBAC model (i.e. how users are expected to work) with a RBAC model (i.e. how users have actually worked) derived from event logs. To do that, we transform RBAC models to graphs and analyze them for structural similarities and differences. Differences can indicate security violations such as unauthorized access. For future work, we plan to investigate semantic differences between RBAC models.
Top- Leitner, Maria
Category |
Paper in Conference Proceedings or in Workshop Proceedings (Full Paper in Proceedings) |
Event Title |
14th International Conference on Computer Aided Systems Theory (EUROCAST 2013) |
Divisions |
Workflow Systems and Technology |
Event Location |
Las Palmas, Gran Canaria |
Event Type |
Conference |
Event Dates |
10-15 February 2013 |
Series Name |
Lecture Notes in Computer Science |
ISSN/ISBN |
978-3-642-53856-8 |
Publisher |
Springer |
Page Range |
pp. 507-514 |
Date |
2013 |
Export |