Journal on Communications ›› 2017, Vol. 38 ›› Issue (12): 63-72.doi: 10.11959/j.issn.1000-436x.2017285

• Papers • Previous Articles     Next Articles

Spectral-clustering-based abnormal permission assignments hunting framework

Liang FANG1,2,Li-hua YIN3,Feng-hua LI2,Bin-xing FANG1,3,4   

  1. 1 School of CyberSpace Security,Beijing University of Posts and Telecommunications,Beijing 100876,China
    2 State Key Laboratory of Information Security,Institute of Information Engineering,Chinese Academy of Sciences,Beijing 100093,China
    3 Cyberspace Institute of Advanced Technology,Guangdong University,Guangzhou 510006,China
    4 Institute of Electronic and Information Engineering of UESTC in Guangdong,Dongguan 523808,China
  • Revised:2017-11-06 Online:2017-12-01 Published:2018-01-19
  • Supported by:
    The National Key Research and Development Program of China(2016YFB0801001);The National Natural Science Foundation of China(61672515);Dongguan Innovative Research Team Program(201636000100038)

Abstract:

Migrating traditional access control,such as mandatory and discretionary access control,into role-based access control(RBAC)lightens a practical way to improve the user-permission management efficiency.To guarantee the security of RBAC system,it is important to generate proper roles during the migration.However,abnormal user-permission configurations lead to wrong roles and cause tremendous security risks.To hunt the potential abnormal user-permission configurations,a novel spectral clustering based abnormal configuration hunting framework was proposed and recommendations were given to correct these configurations.Experimental results show its performance over existing solutions.

Key words: access control, abnormal configurations, spectral clustering

CLC Number: 

No Suggested Reading articles found!