Showing posts with label Role Engineering. Show all posts
Showing posts with label Role Engineering. Show all posts

Wednesday, January 7, 2009

Alessandro strikes again!

Two new Technical Papers, “Mining Stable Roles in RBAC”, and “A Probabilistic Bound on the Basic Role Mining Problem and its Applications” have been recently accepted and will be presented, by my colleague Alessandro Colantonio, at the coming IFIP/SEC-2009- 24th IFIP International Information Security Conference, Pafos, Cyprus, May 18-20, 2008.

I am not an expert in the used theoretical and mathematical concepts, but I find the global effort to minimize complexity very insightful. Clearly, keeping the number of different roles sufficiently small is an important aspects. But there are many other aspects being equally important, in particular roles should reflect the organizational structure, should be acceptable by human users, easy to update, and should consider business constraints. The papers highlight some basic features on which Engiweb Security “IDEAS Role Constructor” module is based.

The abstracts:

A Probabilistic Bound on the Basic Role Mining Problem and its Applications
In this paper we describe a new probabilistic approach to the role engineering process for RBAC. In particular, we address the issue of minimizing the number of roles, problem known in literature as the Basic Role Mining Problem (basicRMP). We leverage the equivalence of the above issue with the vertex coloring problem. Our main result is the proof that the minimum number of roles is sharply concentrated around its expected value. A further contribution is to show how this result can be applied as a stop condition when striving to find out an approximation for the basicRMP.
We also show that the proposal can be used to decide whether it is advisable to undertake the efforts to renew an RBAC state. Note that both these applications can result in a substantial saving of resources. A thorough analysis using advanced probabilistic tools supports our results.
Finally, further relevant research directions are also highlighted.

Mining Stable Roles in RBAC
In this paper we address the problem of generating a candidate role set for an RBAC configuration that enjoys the following two key features: it minimizes the administration cost; and, it is a stable candidate role-set.
To achieve these goals, we implement a three steps methodology: first, we associate a weight to roles; second, we identify and remove the user-permission assignments that can not belong to a role having a weight exceeding a given threshold; third, we restrict the problem of finding a candidate role-set for the given system configuration using only the user-permission assignments that have not been removed in step two (that is, user-permission assignments that belong to roles having a weight exceeding the given threshold). We formally show-proof of our results are rooted in graph theory-that this methodology achieves the intended goals.
Finally, we discuss practical applications of our approach to the role mining problem.

Authors: Alessandro Colantonio, Roberto Di Pietro, Alberto Ocello, Nino Verde.

If you are interested in receiving the full texts, please send me an e-mail: my surname at eng dot it.

Monday, May 19, 2008

New Technical Paper on Role Mining

A new Technical Paper, “Leveraging Lattices to Improve Role Mining”, has been recently accepted and will be presented at the coming SEC 2008 23rd International Information Security Conference, co-located with IFIP World Computer Congress 2008, Milan, Italy, September 8-10, 2008.
Topics of interest of this conference include, but are not limited to:
  • Access control
  • Security and Content Policies
  • Role Mining
  • Security Compliance
  • Identity and Trust Management
The paper highlights some crucial aspects on which Engiweb Security “IDEAS Role Constructor” module is based.

Abstract:
“In this paper we provide a new formal framework applicable to Role Mining algorithms.
This framework is based on a rigorous analysis of identifiable patterns in access permission data. In particular, it is possible to derive a lattice of candidate roles from the permission powerset.
We formally prove some interesting properties about such lattices. These properties, a contribution on their own, can be applied practically to optimize role mining algorithms. Data redundancies associated with co-occurrences of permissions among users can be easily identified and eliminated, allowing for increased output quality and reduced processing time.
To prove the effectiveness of our proposal, we have applied our results to two existing role mining algorithms: Apriori and RBAM. Application of these modified algorithms to a realistic data set consistently reduced running time and, in some cases, also greatly improved output quality; all of which confirmed our analytical findings.”
Authors: Alessandro Colantonio, Roberto Di Pietro, Alberto Ocello

Nice, Friends!, But, pardon me if I find much more pleasant another kind of Lattice: A nice piece of the Rhubarb-Strawberry Lattice Tart really hits the spot!

BTW if you are interested in receiving the full text, please send me an e-mail: my surname at eng dot it.

Tuesday, November 20, 2007

A white paper on "Role Engineering"

This blog has also been set up to pass along supporting documents from people working at Engiweb Security, to send news and get feedback from the IAM community. So.....

My colleague Alessandro Colantonio has just released a white paper entitled “Cost-driven approach to role engineering”. You can download a copy here.
"Cost-driven" is the philosophy that inspires Engiweb Security's “Role Constructor” module.

In general most proposed methodologies lack a formal metric to capture the “interest” or “quality” of proposed roles. To address this problem, Engiweb Security's role discovery tool can identify a role-set that minimizes the administration cost, by measuring and evaluating cost advantages during the entire role-set definition process.

Various elements can influence the administration “cost”:

  • Number of roles, role-to-user assignment, role-to-permission assignment and hierarchical relationships;
  • Business process and activity modeling;
  • SoD constraints, Temporal constraints, Cardinality constraints, etc.;
  • User attributes (organizational unit, business function, physical location, etc.);
  • Actual usage frequency of IT resources, …….

Furthermore, the developed algorithm can easily be scaled to manage huge RBAC role engineering tasks, such as those usually encountered during a large Identity and Access Management projects.

Alessandro will better describe our approach, speaking at the “The 23rd ACM Symposium on Applied Computing” to be held in Fortaleza, CearĂ¡, Brazil, March 16 – 20, 2008.