TY - BOOK
T1 - Role mining in business: Taming role-based access control administration
AU - Colantonio, Alessandro
AU - Di Pietro, Roberto
AU - Ocello, Alberto
N1 - Generated from Scopus record by KAUST IRTS on 2023-09-20
PY - 2012/1/1
Y1 - 2012/1/1
N2 - With continuous growth in the number of information objects and the users that can access these objects, ensuring that access is compliant with company policies has become a big challenge. Role-based Access Control (RBAC)-a policy-neutral access control model that serves as a bridge between academia and industry-is probably the most suitable security model for commercial applications. Interestingly, role design determines RBAC’s cost. When there are hundreds or thousands of users within an organization, with individual functions and responsibilities to be accurately reflected in terms of access permissions, only a well-defined role engineering process allows for significant savings of time and money while protecting data and systems. Among role engineering approaches, searching through access control systems to find de facto roles embedded in existing permissions is attracting increasing interest. The focus falls on role mining, which is applied data mining techniques to automate-to the extent possible-the role design task. This book explores existing role mining algorithms and offers insights into the automated role design approaches proposed in the literature. Alongside theory, this book acts as a practical guide for using role mining tools when implementing RBAC. Besides a comprehensive surveyof role mining techniques deeply rooted in academic research, this book also provides a summary of the role-based approach, access control concepts and describes a typical role engineering process.Among the pioneering works on role mining, this book blends business elements with data mining theory, and thus further extends the applications of role mining into business practice. This makes it a useful guide for all academics, IT and business professionals.
AB - With continuous growth in the number of information objects and the users that can access these objects, ensuring that access is compliant with company policies has become a big challenge. Role-based Access Control (RBAC)-a policy-neutral access control model that serves as a bridge between academia and industry-is probably the most suitable security model for commercial applications. Interestingly, role design determines RBAC’s cost. When there are hundreds or thousands of users within an organization, with individual functions and responsibilities to be accurately reflected in terms of access permissions, only a well-defined role engineering process allows for significant savings of time and money while protecting data and systems. Among role engineering approaches, searching through access control systems to find de facto roles embedded in existing permissions is attracting increasing interest. The focus falls on role mining, which is applied data mining techniques to automate-to the extent possible-the role design task. This book explores existing role mining algorithms and offers insights into the automated role design approaches proposed in the literature. Alongside theory, this book acts as a practical guide for using role mining tools when implementing RBAC. Besides a comprehensive surveyof role mining techniques deeply rooted in academic research, this book also provides a summary of the role-based approach, access control concepts and describes a typical role engineering process.Among the pioneering works on role mining, this book blends business elements with data mining theory, and thus further extends the applications of role mining into business practice. This makes it a useful guide for all academics, IT and business professionals.
UR - http://www.worldscientific.com/worldscibooks/10.1142/8292
UR - http://www.scopus.com/inward/record.url?scp=84995493943&partnerID=8YFLogxK
U2 - 10.1142/8292
DO - 10.1142/8292
M3 - Book
SN - 9789814366151
BT - Role mining in business: Taming role-based access control administration
PB - World Scientific Publishing Co.
ER -