Delta Analysis of Role-Based Access Control Models

Delta Analysis of Role-Based Access Control Models

Abstract

Role-based Access Control (RBAC) is de facto standard for access control in Process-aware Information Systems (PAIS); it grants authorization to users based on roles (i.e. sets of permissions). So far, research has centered on the design and run time aspects of RBAC. An evaluation and verification of a RBAC system (e.g., to evaluate ex post which users acting in which roles were authorized to execute permissions) is still missing. In this paper, we propose delta analysis of RBAC models which compares a prescriptive RBAC model (i.e. how users are expected to work) with a RBAC model (i.e. how users have actually worked) derived from event logs. To do that, we transform RBAC models to graphs and analyze them for structural similarities and differences. Differences can indicate security violations such as unauthorized access. For future work, we plan to investigate semantic differences between RBAC models.

Grafik Top
Authors
  • Leitner, Maria
Grafik Top
Projects
Grafik Top
Shortfacts
Category
Paper in Conference Proceedings or in Workshop Proceedings (Full Paper in Proceedings)
Event Title
14th International Conference on Computer Aided Systems Theory (EUROCAST 2013)
Divisions
Workflow Systems and Technology
Event Location
Las Palmas, Gran Canaria
Event Type
Conference
Event Dates
10-15 February 2013
Series Name
Lecture Notes in Computer Science
ISSN/ISBN
978-3-642-53856-8
Publisher
Springer
Page Range
pp. 507-514
Date
2013
Export
Grafik Top