错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Behavior-Dependent Access Control Policies

  • Amour Shmuel,
  • Ehud Gudes

摘要

Organizations use Role-based access control (RBAC) and Attribute-based access control (ABAC) to assign permissions to employees and ensure that junior-level staff does not access sensitive information or high-level tasks. However, managing these mechanisms can be challenging, especially for mid-level and larger organizations with thousands of employees working across hundreds of projects and multiple locations. Employees frequently change roles and departments, complicating the issue. To address this challenge, organizations typically rely on either a Strict Policy approach or a Permissive Policy approach. A Strict Policy requires users to work hard and the information security officer (CISO) department to work even harder, managing and approving access permissions, but it can lead to delays in work progress. A Permissive Policy prioritizes fast work progress and grants permissions more liberally, but it can expose users to sensitive data and require the organization to run endless monitoring applications to detect any access anomalies. The aim of our paper is to explore the utilization of previously approved or denied user access policies to authorize new access requests. The new requests could pertain to a variety of scenarios, such as an existing user seeking access to a familiar resource, a new user requesting access to an established resource, or an existing user requesting access to an entirely new resource.