ROLE MINING IN BUSINESS: TAMING ROLE-BASED ACCESS CONTROL ADMINISTRATION
暫譯: 商業中的角色挖掘:馴服基於角色的存取控制管理

Roberto Di Pietro, Alessandro Colantonio, Alberto Ocello

  • 出版商: World Scientific Pub
  • 出版日期: 2012-02-24
  • 售價: $4,320
  • 貴賓價: 9.5$4,104
  • 語言: 英文
  • 頁數: 274
  • 裝訂: Hardcover
  • ISBN: 9814374008
  • ISBN-13: 9789814374002
  • 海外代購書籍(需單獨結帳)

相關主題

商品描述

With continuous growth in the number of information objects and the users that can access these objects, ensuring that access is compliant with company policies has become a big challenge. Role-based Access Control (RBAC) -- a policy-neutral access control model that serves as a bridge between academia and industry -- is probably the most suitable security model for commercial applications.

Interestingly, role design determines RBAC's cost. When there are hundreds or thousands of users within an organization, with individual functions and responsibilities to be accurately reflected in terms of access permissions, only a well-defined role engineering process allows for significant savings of time and money while protecting data and systems.

Among role engineering approaches, searching through access control systems to find de facto roles embedded in existing permissions is attracting increasing interest. The focus falls on role mining, which is applied data mining techniques to automate -- to the extent possible -- the role design task.

This book explores existing role mining algorithms and offers insights into the automated role design approaches proposed in the literature. Alongside theory, this book acts as a practical guide for using role mining tools when implementing RBAC. Besides a comprehensive survey of role mining techniques deeply rooted in academic research, this book also provides a summary of the role-based approach, access control concepts and describes a typical role engineering process.

Among the pioneering works on role mining, this book blends business elements with data mining theory, and thus further extends the applications of role mining into business practice. This makes it a useful guide for all academics, IT and business professionals.

商品描述(中文翻譯)

隨著資訊物件數量和能夠訪問這些物件的用戶不斷增長,確保訪問符合公司政策已成為一個重大挑戰。基於角色的訪問控制(Role-based Access Control, RBAC)是一種政策中立的訪問控制模型,作為學術界與業界之間的橋樑,可能是商業應用中最合適的安全模型。

有趣的是,角色設計決定了RBAC的成本。當一個組織內有數百或數千名用戶時,個別功能和責任必須準確反映在訪問權限上,只有明確定義的角色工程流程才能在保護數據和系統的同時,顯著節省時間和金錢。

在角色工程方法中,通過訪問控制系統尋找嵌入在現有權限中的事實角色的研究正受到越來越多的關注。重點放在角色挖掘(role mining)上,這是一種應用數據挖掘技術來自動化角色設計任務的方式,盡可能地提高自動化程度。

本書探討現有的角色挖掘算法,並提供文獻中提出的自動化角色設計方法的見解。除了理論之外,本書還作為實用指南,幫助在實施RBAC時使用角色挖掘工具。除了對深植於學術研究的角色挖掘技術進行全面調查外,本書還提供了基於角色的方法、訪問控制概念的總結,並描述了一個典型的角色工程流程。

在角色挖掘的開創性工作中,本書將商業元素與數據挖掘理論相結合,進一步擴展了角色挖掘在商業實踐中的應用。這使得本書成為所有學術界、IT和商業專業人士的有用指南。