DocumentCode :
1447011
Title :
Visual Role Mining: A Picture Is Worth a Thousand Roles
Author :
Colantonio, Alessandro ; Pietro, Roberto Di ; Ocello, Alberto ; Verde, Nino Vincenzo
Author_Institution :
Bay31 GmbH, Zug, Switzerland
Volume :
24
Issue :
6
fYear :
2012
fDate :
6/1/2012 12:00:00 AM
Firstpage :
1120
Lastpage :
1133
Abstract :
This paper offers a new role engineering approach to Role-Based Access Control (RBAC), referred to as visual role mining. The key idea is to graphically represent user-permission assignments to enable quick analysis and elicitation of meaningful roles. First, we formally define the problem by introducing a metric for the quality of the visualization. Then, we prove that finding the best representation according to the defined metric is a NP-hard problem. In turn, we propose two algorithms: ADVISER and EXTRACT. The former is a heuristic used to best represent the user-permission assignments of a given set of roles. The latter is a fast probabilistic algorithm that, when used in conjunction with ADVISER, allows for a visual elicitation of roles even in absence of predefined roles. Besides being rooted in sound theory, our proposal is supported by extensive simulations run over real data. Results confirm the quality of the proposal and demonstrate its viability in supporting role engineering decisions.
Keywords :
authorisation; computational complexity; data mining; data visualisation; probability; ADVISER algorithm; EXTRACT algorithm; NP-hard problem; probabilistic algorithm; role engineering approach; role visual elicitation; role-based access control; sound theory; user-permission assignments; visual role mining; visualization quality; Access control; Algorithm design and analysis; Business; Data mining; Data visualization; Itemsets; Visualization; Access controls; data and knowledge visualization; mining methods and algorithms.;
fLanguage :
English
Journal_Title :
Knowledge and Data Engineering, IEEE Transactions on
Publisher :
ieee
ISSN :
1041-4347
Type :
jour
DOI :
10.1109/TKDE.2011.37
Filename :
5710922
Link To Document :
بازگشت