Skip to Main Content (Press Enter)

Logo CNR
  • ×
  • Home
  • Persone
  • Pubblicazioni
  • Strutture
  • Competenze

UNI-FIND
Logo CNR

|

UNI-FIND

cnr.it
  • ×
  • Home
  • Persone
  • Pubblicazioni
  • Strutture
  • Competenze
  1. Pubblicazioni

Towards Attribute-based Access Control Policy Engineering Using Risk

Contributo in Atti di convegno
Data di Pubblicazione:
2013
Abstract:
Attribute-based Access Control (ABAC) was recently proposed as a general model which is able to capture the main existing access control models. This paper discusses the problems of configuring ABAC and engineering access policies. We question how to design attributes, how to assign attributes to subjects, objects, actions, and how to formulate access policies which bind subjects to objects and actions via attributes. Inspired by the role mining problem in Role-based Access Control, in this paper we propose the first attempt to formalise ABAC in a matrix form and define formally a problem of access policy engineering. Our approach is based on the XACML standard to be more practical.
Tipologia CRIS:
04.01 Contributo in Atti di convegno
Keywords:
ABAC; policy engineering; access control; attributes; attribute mining problem (AMP); role mining
Elenco autori:
Lazouski, Aliaksandr; Yautsiukhin, Artsiom; Krautsevich, Leanid; Martinelli, Fabio; Mori, Paolo
Autori di Ateneo:
MARTINELLI FABIO
YAUTSIUKHIN ARTSIOM
Link alla scheda completa:
https://iris.cnr.it/handle/20.500.14243/250327
  • Utilizzo dei cookie

Realizzato con VIVO | Designed by Cineca | 26.5.0.0 | Sorgente dati: PREPROD (Ribaltamento disabilitato)