{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,9]],"date-time":"2026-05-09T17:09:39Z","timestamp":1778346579067,"version":"3.51.4"},"publisher-location":"Cham","reference-count":34,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031965890","type":"print"},{"value":"9783031965906","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-031-96590-6_22","type":"book-chapter","created":{"date-parts":[[2025,6,23]],"date-time":"2025-06-23T04:58:47Z","timestamp":1750654727000},"page":"413-424","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Transaction Logs in\u00a0Access Control: Leveraging an Under-Utilized Data Source"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7082-000X","authenticated-orcid":false,"given":"Sascha","family":"Kern","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0157-3057","authenticated-orcid":false,"given":"Thomas","family":"Baumer","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-2660-6537","authenticated-orcid":false,"given":"Raphael","family":"Neudert","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1338-9003","authenticated-orcid":false,"given":"G\u00fcnther","family":"Pernul","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,6,24]]},"reference":[{"key":"22_CR1","doi-asserted-by":"publisher","first-page":"86872","DOI":"10.1109\/ACCESS.2023.3304270","volume":"11","author":"T Baumer","year":"2023","unstructured":"Baumer, T., M\u00fcller, M., Pernul, G.: System for cross-domain identity management (SCIM): survey and enhancement with RBAC. IEEE Access 11, 86872\u201386894 (2023)","journal-title":"IEEE Access"},{"key":"22_CR2","doi-asserted-by":"publisher","unstructured":"Baumer, T., Reittinger, T., Kern, S., Pernul, G.: Digital nudges for access reviews: guiding deciders to revoke excessive authorizations. In: Proceedings of the Twentieth USENIX Conference on Usable Privacy and Security, SOUPS 2024. USENIX Association, USA (2024). https:\/\/doi.org\/10.5555\/3696899.3696912","DOI":"10.5555\/3696899.3696912"},{"key":"22_CR3","unstructured":"Beck, R., Czepluch, J.S., Lollike, N., Malone, S.: Blockchain\u2013the gateway to trust-free cryptographic transactions. In: Twenty-Fourth European Conference on Information Systems (ECIS), \u0130stanbul, Turkey, pp. 1\u201314. Springer (2016)"},{"key":"22_CR4","doi-asserted-by":"crossref","unstructured":"Benedetti, M., Mori, M.: Parametric RBAC maintenance via max-SAT. In: Proceedings of the 23nd ACM on Symposium on Access Control Models and Technologies, pp. 15\u201325 (2018)","DOI":"10.1145\/3205977.3205987"},{"key":"22_CR5","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1186\/s42400-019-0036-9","volume":"2","author":"M Benedetti","year":"2019","unstructured":"Benedetti, M., Mori, M.: On the use of max-SAT and PDDL in RBAC maintenance. Cybersecurity 2, 1\u201325 (2019)","journal-title":"Cybersecurity"},{"key":"22_CR6","doi-asserted-by":"crossref","unstructured":"Benkaouz, Y., Erradi, M., Freisleben, B.: Work in progress: K-nearest neighbors techniques for ABAC policies clustering. In: Proceedings of the 2016 ACM International Workshop on Attribute Based Access Control, pp. 72\u201375 (2016)","DOI":"10.1145\/2875491.2875497"},{"key":"22_CR7","doi-asserted-by":"crossref","unstructured":"Buffardi, K.: Assessing individual contributions to software engineering projects with git logs and user stories. In: Proceedings of the 51st ACM Technical Symposium on Computer Science Education, pp. 650\u2013656 (2020)","DOI":"10.1145\/3328778.3366948"},{"key":"22_CR8","doi-asserted-by":"publisher","unstructured":"Cao, Y., Yang, L.: A survey of identity management technology. In: 2010 IEEE International Conference on Information Theory and Information Security, pp. 287\u2013293 (2010). https:\/\/doi.org\/10.1109\/ICITIS.2010.5689468","DOI":"10.1109\/ICITIS.2010.5689468"},{"key":"22_CR9","unstructured":"Davis, T., Shaw, G., Delaney, K.: SQL Server Transaction Log Management. Simple Talk Pub. (2012)"},{"key":"22_CR10","unstructured":"Fuchs, L., Kunz, M., Pernul, G.: Role model optimization for secure role-based identity management. In: European Conference on Information Systems (ECIS), pp. 1\u201315. AIS, Tel Aviv (2014). https:\/\/epub.uni-regensburg.de\/30394\/"},{"key":"22_CR11","doi-asserted-by":"publisher","unstructured":"Fuchs, L., Pernul, G.: Supporting compliant and secure user handling - a structured approach for in-house identity management. In: The Second International Conference on Availability, Reliability and Security (ARES 2007), pp. 374\u2013384. IEEE, Vienna (2007). https:\/\/doi.org\/10.1109\/ARES.2007.145","DOI":"10.1109\/ARES.2007.145"},{"key":"22_CR12","doi-asserted-by":"crossref","unstructured":"Fuchs, L., Pernul, G.: Hydro\u2013hybrid development of roles. In: Information Systems Security: 4th International Conference, ICISS 2008, Hyderabad, India, 16\u201320 December 2008. Proceedings 4, pp. 287\u2013302. Springer (2008)","DOI":"10.1007\/978-3-540-89862-7_24"},{"key":"22_CR13","doi-asserted-by":"crossref","unstructured":"Groll, S., Kern, S., Fuchs, L., Pernul, G.: Monitoring access reviews by crowd labelling. In: Trust, Privacy and Security in Digital Business: 18th International Conference, TrustBus 2021, Virtual Event, 27\u201330 September 2021, Proceedings 18, pp. 3\u201317. Springer (2021)","DOI":"10.1007\/978-3-030-86586-3_1"},{"issue":"5","key":"22_CR14","doi-asserted-by":"publisher","first-page":"48","DOI":"10.1109\/MSP.2011.72","volume":"9","author":"CA Gunter","year":"2011","unstructured":"Gunter, C.A., Liebovitz, D., Malin, B.: Experience-based access management: a life-cycle framework for identity and access management systems. IEEE Secur. Priv. 9(5), 48 (2011)","journal-title":"IEEE Secur. Priv."},{"key":"22_CR15","doi-asserted-by":"crossref","unstructured":"Hasel\u00a0Mehri, G., Wester, I.L., Paci, F., Zannone, N.: Mitigating privilege misuse in access control through anomaly detection. In: Proceedings of the 18th International Conference on Availability, Reliability and Security, ARES 2023. Association for Computing Machinery, New York (2023)","DOI":"10.1145\/3600160.3604988"},{"key":"22_CR16","doi-asserted-by":"crossref","unstructured":"Hein, P., Biswas, D., Martucci, L.A., Muhlhauser, M.: Conflict detection and lifecycle management for access control in publish\/subscribe systems. In: 2011 IEEE 13th International Symposium on High-Assurance Systems Engineering, pp. 104\u2013111. IEEE (2011)","DOI":"10.1109\/HASE.2011.50"},{"key":"22_CR17","unstructured":"Hunt, P., Cam-Winget, N., Kiser, M., Schreiber, J.: SCIM profile for security event tokens. internet-draft draft-ietf-scim-events-07. Internet Engineering Task Force (2024). Work in Progress"},{"key":"22_CR18","unstructured":"Jaferian, P., Rashtian, H., Beznosov, K.: To authorize or not authorize: helping users review access policies in organizations. In: 10th Symposium On Usable Privacy and Security (SOUPS 2014), pp. 301\u2013320 (2014)"},{"issue":"4","key":"22_CR19","doi-asserted-by":"publisher","first-page":"2304","DOI":"10.1109\/TDSC.2021.3054331","volume":"19","author":"L Karimi","year":"2021","unstructured":"Karimi, L., Aldairi, M., Joshi, J., Abdelhakim, M.: An automatic attribute-based access control policy extraction from access logs. IEEE Trans. Dependable Secure Comput. 19(4), 2304\u20132317 (2021)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"22_CR20","doi-asserted-by":"publisher","unstructured":"Kern, S., Baumer, T., Fuchs, L., Pernul, G.: Maintain high-quality access control policies: an academic and practice-driven approach. In: Atluri, V., Ferrara, A.L. (eds.) DBSec 2023. LNCS, vol. 13942, pp. 223\u2013242. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-37586-6_14","DOI":"10.1007\/978-3-031-37586-6_14"},{"key":"22_CR21","first-page":"103301","volume":"70","author":"S Kern","year":"2022","unstructured":"Kern, S., Baumer, T., Groll, S., Fuchs, L., Pernul, G.: Optimization of access control policies. J. Inf. Secur. Appl. 70, 103301 (2022)","journal-title":"J. Inf. Secur. Appl."},{"key":"22_CR22","doi-asserted-by":"crossref","unstructured":"Leitner, M., Rinderle-Ma, S.: Anomaly detection and visualization in generative RBAC models. In: Proceedings of the 19th ACM Symposium on Access Control Models and Technologies, pp. 41\u201352 (2014)","DOI":"10.1145\/2613087.2613105"},{"key":"22_CR23","doi-asserted-by":"publisher","unstructured":"Mitra, B., Sural, S., Vaidya, J., Atluri, V.: A survey of role mining. ACM Comput. Surv. 48(4) (2016). https:\/\/doi.org\/10.1145\/2871148","DOI":"10.1145\/2871148"},{"issue":"4","key":"22_CR24","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/1880022.1880030","volume":"13","author":"I Molloy","year":"2010","unstructured":"Molloy, I., Chen, H., Li, T., Wang, Q., Li, N., Bertino, E., Calo, S., Lobo, J.: Mining roles with multiple objectives. ACM Trans. Inf. Syst. Secur. (TISSEC) 13(4), 1\u201335 (2010)","journal-title":"ACM Trans. Inf. Syst. Secur. (TISSEC)"},{"key":"22_CR25","doi-asserted-by":"crossref","unstructured":"Morisset, C., Sanchez, D.: VisABAC: a tool for visualising ABAC policies. In: ICISSP, pp. 117\u2013126 (2018)","DOI":"10.5220\/0006647401170126"},{"key":"22_CR26","doi-asserted-by":"crossref","unstructured":"Pang, C., Hansen, D., Maeder, A.: Managing RBAC states with transitive relations. In: Proceedings of the 2nd ACM Symposium on Information, Computer and Communications Security, pp. 139\u2013148 (2007)","DOI":"10.1145\/1229285.1229306"},{"key":"22_CR27","doi-asserted-by":"crossref","unstructured":"Parkinson, S., Khan, S.: A survey on empirical security analysis of access-control systems: a real-world perspective. ACM Comput. Surv. 55(6) (2022)","DOI":"10.1145\/3533703"},{"issue":"2","key":"22_CR28","doi-asserted-by":"publisher","first-page":"94","DOI":"10.1080\/10580530.2020.1738601","volume":"38","author":"A Schrimpf","year":"2021","unstructured":"Schrimpf, A., Drechsler, A., Dagianis, K.: Assessing identity and access management process maturity: first insights from the German financial sector. Inf. Syst. Manag. 38(2), 94\u2013115 (2021)","journal-title":"Inf. Syst. Manag."},{"key":"22_CR29","unstructured":"Shen, B., Shan, T., Zhou, Y.: Improving logging to reduce permission over-granting mistakes. In: 32nd USENIX Security Symposium (USENIX Security 2023), pp. 409\u2013426. USENIX Association, Anaheim (2023)"},{"issue":"4","key":"22_CR30","doi-asserted-by":"publisher","first-page":"3158","DOI":"10.1109\/TDSC.2022.3197265","volume":"20","author":"F Skopik","year":"2023","unstructured":"Skopik, F., Wurzenberger, M., H\u00f6ld, G., Landauer, M., Kuhn, W.: Behavior-based anomaly detection in log data of physical access control systems. IEEE Trans. Dependable Secure Comput. 20(4), 3158\u20133175 (2023)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"issue":"1","key":"22_CR31","doi-asserted-by":"publisher","first-page":"28","DOI":"10.1109\/MSP.2010.46","volume":"8","author":"M Strembeck","year":"2010","unstructured":"Strembeck, M.: Scenario-driven role engineering. IEEE Secur. Priv. 8(1), 28\u201335 (2010)","journal-title":"IEEE Secur. Priv."},{"issue":"2","key":"22_CR32","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/2229156.2229157","volume":"3","author":"W Van Der Aalst","year":"2012","unstructured":"Van Der Aalst, W.: Process mining: overview and opportunities. ACM Trans. Manage. Inf. Syst. (TMIS) 3(2), 1\u201317 (2012)","journal-title":"ACM Trans. Manage. Inf. Syst. (TMIS)"},{"issue":"4","key":"22_CR33","doi-asserted-by":"publisher","first-page":"866","DOI":"10.1287\/ijoc.2014.0603","volume":"26","author":"H Xia","year":"2014","unstructured":"Xia, H., Dawande, M., Mookerjee, V.: Role refinement in access control: model and analysis. INFORMS J. Comput. 26(4), 866\u2013884 (2014)","journal-title":"INFORMS J. Comput."},{"key":"22_CR34","doi-asserted-by":"crossref","unstructured":"Xiang, C., et al.: Towards continuous access control validation and forensics. In: Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, pp. 113\u2013129 (2019)","DOI":"10.1145\/3319535.3363191"}],"container-title":["Lecture Notes in Computer Science","Data and Applications Security and Privacy XXXIX"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-96590-6_22","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,9]],"date-time":"2026-05-09T16:19:44Z","timestamp":1778343584000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-96590-6_22"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"ISBN":["9783031965890","9783031965906"],"references-count":34,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-96590-6_22","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]},"assertion":[{"value":"24 June 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"DBSec","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"IFIP Annual Conference on Data and Applications Security and Privacy","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Gj\u00f8vik","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Norway","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"23 June 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"24 June 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"39","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"dbsec2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.ntnu.edu\/web\/dbsec2025\/dbsec2025","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}