Polisma - A Framework for Learning Attribute-based Access Control Policies

Abstract Attribute-based access control (ABAC) is being widely adopted due to its flexibility and universality in capturing authorizations in terms of the properties (attributes) of users and resources. However, specifying ABAC policies is a complex task due to the variety of such attributes. Moreover, migrating an access control system adopting a low-level model to ABAC can be challenging. An approach for generating ABAC policies is to learn them from data, namely from logs of historical access requests and their corresponding decisions. This paper proposes a novel framework for learning ABAC policies from data. The framework, referred to as Polisma, combines data mining, statistical, and machine learning techniques. Polisma capitalizes on potential context information obtained from external sources (e.g., LDAP directories) to enhance the learning process. The approach is evaluated empirically using two datasets (real and synthetic). Experimental results show that Polisma is able to generate ABAC policies that accurately control access requests.
Authors
  • Amani Abu Jabal (Purdue)
  • Elisa Bertino (Purdue)
  • Jorge Lobo
  • Mark Law (Imperial)
  • Alessandra Russo (Imperial)
  • Seraphin Calo (IBM US)
  • Dinesh Verma (IBM US)
Date Sep-2019
Venue Annual Fall Meeting of the DAIS ITA, 2019