• DocumentCode
    1725787
  • Title

    An Approach to Bridge the Gap between Role Mining and Role Engineering via Migration Guides

  • Author

    Baumgrass, Anne ; Strembeck, Mark

  • Author_Institution
    Inst. for Inf. Syst. & New Media, Vienna Univ. of Econ. & Bus. WU Vienna, Vienna, Austria
  • fYear
    2012
  • Firstpage
    113
  • Lastpage
    122
  • Abstract
    Mining approaches, such as role mining or organizational mining, can be applied to derive permissions and roles from a system´s configuration or from log files. In this way, mining techniques document the current state of a system and produce current-state RBAC models. However, such current-state RBAC models most often follow from structures that have evolved over time and are not the result of a systematic rights management procedure. In contrast, role engineering is applied to define a tailored RBAC model for a particular organization or information system. Thus, role engineering techniques produce a target-state RBAC model that is customized for the business processes supported via the respective information system. The migration from a current-state RBAC model to a tailored target-state RBAC model is, however, a complex task. In this paper, we present a systematic approach to migrate current-state RBAC models to target-state RBAC models. In particular, we use model comparison techniques to identify differences between two RBAC models. Based on these differences, we derive migration rules that define which elements and element relations must be changed, added, or removed. A migration guide then includes all migration rules that need to be applied to a particular current-state RBAC model to produce the corresponding target-state RBAC model. In addition, we discuss different options for tool support and describe our implementation for the derivation of migration guides which is based on the Eclipse Modeling Framework (EMF).
  • Keywords
    authorisation; business data processing; data mining; information systems; organisational aspects; EMF; business processes; current-state RBAC models; eclipse modeling framework; information system; log files; migration guides; organizational mining; role engineering; role mining; system configuration; systematic rights management procedure; tool support; Adaptation models; Biological system modeling; Context; Contracts; Information systems; Unified modeling language; Visualization; Migration; Migration Guide; RBAC; RBAC Comparison; Role Engineering; Role Mining;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Availability, Reliability and Security (ARES), 2012 Seventh International Conference on
  • Conference_Location
    Prague
  • Print_ISBN
    978-1-4673-2244-7
  • Type

    conf

  • DOI
    10.1109/ARES.2012.77
  • Filename
    6329171