A Similarity Measure for Comparing Access Control Policies

semanticscholar(2009)

引用 3|浏览3
暂无评分
摘要
Recent collaborative applications and enterprises very often need to efficiently integrate their access control policies. An important step in policy integration is to analyze the similarity of policies. Existing approaches to policy similarity analysis are mainly based on logical reasoning and Boolean function comparison. Such approaches are computationally expensive and do not scale well for large heterogeneous distributed environments (like Grid computing systems). In this paper, we propose a policy similarity measure as a filter phase for policy similarity analysis. This measure provides a lightweight approach to pre-compile a large amount of policies and only return the most similar policies for further evaluation. In this paper we formally define the measure by taking into account both the case of categorical attributes and numeric attributes. We solve the problem of name heterogeneity when comparing policies by using ontology matching techniques. Detailed algorithms are presented for the similarly computation. We also present experimental results which demonstrate the efficiency and practical value of our approach.
更多
查看译文
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要