• Home
  • Search
  • Semantically Correct Policy Mining and Enforcement for Attribute based Access Control.
  • Cite Icon2
  • https://doi.org/10.1145/3736764Copy DOI Icon

Semantically Correct Policy Mining and Enforcement for Attribute based Access Control.

Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Attribute-Based Access Control (ABAC) is increasingly becoming popular due to its dynamic, flexible, portable, and scalable nature. Under ABAC, security policies (ABAC rules) are stated in terms of the attributes of the subject, the object and the environment. A subject is granted access to an object if their respective attribute values are satisfied against a set of ABAC rules. Typically hierarchical relationships exist among the subjects as well as the objects, where more specific subjects (objects) inherit the attributes from the general ones. As such, if a subject is allowed access to a general object, that subject is allowed to access all of its sub-types. This has been the general understanding and current ABAC enforcement and policy mining approaches follow this approach. However, in this article, we argue that the general understanding of the semantics of the ABAC is not always appropriate. Indeed, under certain semantics, the specific data may be more sensitive than that of its general counterpart. In that situation, if a subject is allowed access to a general type, it should not be allowed access to its sub-type, which is contrary to the current understanding and implementation. This paper is the first attempt in the literature to distinguish these two different ABAC semantics arising from the different semantics of object attributes themselves. We present concrete examples of these two semantics and demonstrate what can go wrong - both anecdotally as well as empirically - if one ignores the underlying semantics and inappropriately uses the existing enforcement and mining algorithms. We then present how existing algorithms can be modified so that no misconfigurations arise and security is ensured.

Similar Papers
  • Dissertation

Frameworks for Attribute-Based Access Control (ABAC) Policy Engineering

  • Aug 01, 2020
  • Manar Alohaly
  • Conference Article
  • Citations4

A System for Centralized ABAC Policy Administration and Local ABAC Policy Decision and Enforcement in Host Systems using Access Control Lists

  • Mar 14, 2018
  • David Ferraiolo +2
  • Conference Article

Formalizing and Conformance Testing ABAC Policies in Process Logs via an ABAC Metamodel

  • Nov 06, 2025
  • Duc-Hieu Nguyen
  • Research Article
  • Citations11

Contemporaneous Update and Enforcement of ABAC Policies.

  • Jun 07, 2022
  • Proceedings of the ... ACM symposium on access control models and technologies. ACM Symposium on Access Control Models and Technologies
  • Samir Talegaon +4
  • Conference Article
  • Citations38

Representing Attribute Based Access Control Policies in OWL

  • Feb 01, 2016
  • Nitin Kumar Sharma +1
  • Research Article
  • Citations5

A Combination of Semantic and Attribute based Access Control Model for Virtual Organizations

  • Aug 05, 2015
  • Isecure.
  • Morteza Amini +1
  • PDF
  • Research Article
  • Citations2

RESPOnSE-A Framework for Enforcing Risk-Aware Security Policies in Constrained Dynamic Environments.

  • May 23, 2020
  • Sensors
  • Christina Michailidou +4
  • Book Chapter
  • Citations9

Security Analysis of Unified Access Control Policies

  • Jan 01, 2020
  • Mahendra Pratap Singh +3
  • Research Article
  • Citations11

Enhancing Healthcare Security: A Unified RBAC and ABAC Risk-Aware Access Control Approach

  • Jun 14, 2025
  • Future Internet
  • Hany F Atlam +1
  • Research Article

Comparative analysis of a novel smart contract-based hybrid access control model for blockchain-enabled secure IoT home automation systems

  • Jan 01, 2025
  • Journal of Discrete Mathematical Sciences & Cryptography
  • Abhishek Dadhich +2
  • Research Article
  • Citations1

[formula omitted]: A blockchain-based secure access control management for the Internet of Things

  • Oct 30, 2024
  • Journal of Information Security and Applications
  • Utsa Roy +1
  • Conference Article
  • Citations35

Attributed role based access control model

  • Dec 01, 2015
  • Muhammad Umar Aftab +4
  • Conference Article

Modeling the Federal User Identity, Credential, and Access Management (ICAM) decision space to facilitate secure information sharing

  • Nov 01, 2010
  • Thomas C Smith +5
  • PDF
  • Research Article
  • Citations8

Formal Approach to Detect and Resolve Anomalies while Clustering ABAC Policies

  • Dec 11, 2018
  • ICST Transactions on Security and Safety
  • Maryem Ait El Hadj +3
  • Conference Article
  • Citations11

Challenges of “operationalizing” dynamic system access control: Transitioning from ABAC to RAdAC

  • Mar 01, 2012
  • Bassam Farroha +1
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.