首页> 外文期刊>Decision support systems >A new role mining framework to elicit business roles and to mitigate enterprise risk
【24h】

A new role mining framework to elicit business roles and to mitigate enterprise risk

机译:一个新的角色挖掘框架,以吸引业务角色并减轻企业风险

获取原文
获取原文并翻译 | 示例
           

摘要

Role-based access control (RBAC) allows to effectively manage the risk derived from granting access to resources, provided that designed roles are business-driven. Role mining represents an essential tool for role engineers, but existing techniques are not able to elicit roles with an associated clear business meaning. Hence, it is difficult to mitigate risk, to simplify business governance, and to ensure compliance throughout the enterprise. To elicit meaningful roles, we propose a methodology where data to analyze are decomposed into smaller subsets according to the provided business information. We introduce two indices, minability and similarity, that drive the decomposition process by providing the expected complexity to find roles with business meaning. The proposed methodology is rooted on a sound theoretical framework. Moreover, experiments on real enterprise data support its effectiveness.
机译:如果设计的角色是业务驱动的,则基于角色的访问控制(RBAC)可以有效地管理授予资源访问权所带来的风险。角色挖掘是角色工程师必不可少的工具,但是现有技术无法通过明确的业务含义来引发角色。因此,很难降低风险,简化业务管理并确保整个企业的合规性。为了发挥有意义的作用,我们提出一种方法,根据提供的业务信息将要分析的数据分解为较小的子集。我们引入了最小性和相似性两个指标,它们通过提供期望的复杂性来找到具有业务意义的角色来驱动分解过程。所提出的方法基于良好的理论框架。此外,对真实企业数据的实验证明了其有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号