{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,5]],"date-time":"2024-09-05T20:31:35Z","timestamp":1725568295691},"publisher-location":"Berlin, Heidelberg","reference-count":43,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642168246"},{"type":"electronic","value":"9783642168253"}],"license":[{"start":{"date-parts":[[2010,1,1]],"date-time":"2010-01-01T00:00:00Z","timestamp":1262304000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2010]]},"DOI":"10.1007\/978-3-642-16825-3_1","type":"book-chapter","created":{"date-parts":[[2010,11,2]],"date-time":"2010-11-02T13:30:44Z","timestamp":1288704644000},"page":"1-9","source":"Crossref","is-referenced-by-count":0,"title":["Automating Security Configuration and Administration: An Access Control Perspective"],"prefix":"10.1007","author":[{"given":"Jaideep","family":"Vaidya","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"1_CR1","unstructured":"DoD Computer Security Center: Trusted Computer System Evaluation Criteria (December 1985)"},{"key":"1_CR2","doi-asserted-by":"crossref","unstructured":"Bell, D., LaPadula, L.: Secure computer systems: Unified exposition and multics interpretation. Technical Report MTR-2997, The Mitre Corporation, Bedford, MA (March 1976)","DOI":"10.21236\/ADA023588"},{"key":"1_CR3","doi-asserted-by":"crossref","unstructured":"Sandhu, R.S., et al.: Role-based Access Control Models. IEEE Computer, 38\u201347 (February 1996)","DOI":"10.1109\/2.485845"},{"key":"1_CR4","doi-asserted-by":"crossref","unstructured":"Ferraiolo, D., Sandhu, R., Gavrila, S., Kuhn, D., Chandramouli, R.: Proposed NIST Standard for Role-Based Access Control. In: TISSEC (2001)","DOI":"10.1145\/501978.501980"},{"key":"1_CR5","unstructured":"Identity management design guide with ibm tivoli identity. Technical report, IBM (November 2005), http:\/\/www.redbooks.ibm.com\/redbooks\/pdfs\/sg246996.pdf"},{"key":"1_CR6","doi-asserted-by":"crossref","unstructured":"Coyne, E.J.: Role-engineering. In: 1st ACM Workshop on Role-Based Access Control (1995)","DOI":"10.1145\/270152.270159"},{"key":"1_CR7","unstructured":"Gallagher, M.P., O\u2019Connor, A., Kropp, B.: The economic impact of role-based access control. Planning report 02-1, National Institute of Standards and Technology (March 2002)"},{"key":"1_CR8","volume-title":"Role Engineering for Enterprise Security Management","author":"E. Coyne","year":"2007","unstructured":"Coyne, E., Davis, J.: Role Engineering for Enterprise Security Management. Artech House, Norwood (2007)"},{"key":"1_CR9","doi-asserted-by":"crossref","unstructured":"Fernandez, E.B., Hawkins, J.C.: Determining role rights from use cases. In: ACM Workshop on Role-Based Access Control, pp. 121\u2013125 (1997)","DOI":"10.1145\/266741.266767"},{"key":"1_CR10","doi-asserted-by":"crossref","unstructured":"Brooks, K.: Migrating to role-based access control. In: ACM Workshop on Role-Based Access Control, pp. 71\u201381 (1999)","DOI":"10.1145\/319171.319178"},{"key":"1_CR11","doi-asserted-by":"crossref","unstructured":"Roeckle, H., Schimpf, G., Weidinger, R.: Process-oriented approach for role-finding to implement role-based security administraiton in a large industrial organization. In: ACM (ed.) RBAC (2000)","DOI":"10.1145\/344287.344308"},{"key":"1_CR12","doi-asserted-by":"crossref","unstructured":"Shin, D., Ahn, G.J., Cho, S., Jin, S.: On modeling system-centric information for roleengineering. In: 8th ACM Symposium on Access Control Models and Technologies (June 2003)","DOI":"10.1145\/775412.775434"},{"key":"1_CR13","doi-asserted-by":"crossref","unstructured":"Thomsen, D., O\u2019Brien, D., Bogle, J.: Role based access control framework for network enterprises. In: 14th Annual Computer Security Application Conference, pp. 50\u201358 (December 1998)","DOI":"10.1109\/CSAC.1998.738571"},{"key":"1_CR14","doi-asserted-by":"crossref","unstructured":"Neumann, G., Strembeck, M.: A scenario-driven role engineering process for functional rbac roles. In: 7th ACM Symposium on Access Control Models and Technologies (June 2002)","DOI":"10.1145\/507711.507717"},{"key":"1_CR15","doi-asserted-by":"crossref","unstructured":"Epstein, P., Sandhu, R.: Engineering of role\/permission assignment. In: 17th Annual Computer Security Application Conference (December 2001)","DOI":"10.1109\/ACSAC.2001.991529"},{"key":"1_CR16","doi-asserted-by":"crossref","unstructured":"Kern, A., Kuhlmann, M., Schaad, A., Moffett, J.: Observations on the role life-cycle in the context of enterprise security management. In: 7th ACM Symposium on Access Control Models and Technologies (June 2002)","DOI":"10.1145\/507711.507718"},{"key":"1_CR17","doi-asserted-by":"crossref","unstructured":"Schaad, A., Moffett, J., Jacob, J.: The role-based access control system of a european bank: A case study and discussion. In: Proceedings of ACM Symposium on Access Control Models and Technologies, pp. 3\u20139 (May 2001)","DOI":"10.1145\/373256.373257"},{"key":"1_CR18","doi-asserted-by":"crossref","unstructured":"Kuhlmann, M., Shohat, D., Schimpf, G.: Role mining - revealing business roles for security administration using data mining technology. In: Symposium on Access Control Models and Technologies (SACMAT). ACM, New York (June 2003)","DOI":"10.1145\/775412.775435"},{"key":"1_CR19","volume-title":"Symposium on Access Control Models and Technologies (SACMAT)","author":"J. Schlegelmilch","year":"2005","unstructured":"Schlegelmilch, J., Steffens, U.: Role mining with orca. In: Symposium on Access Control Models and Technologies (SACMAT). ACM, New York (June 2005)"},{"key":"1_CR20","doi-asserted-by":"crossref","unstructured":"Vaidya, J., Atluri, V., Warner, J.: Roleminer: mining roles using subset enumeration. In: CCS 2006: Proceedings of the 13th ACM conference on Computer and communications security, pp. 144\u2013153 (2006)","DOI":"10.1145\/1180405.1180424"},{"key":"1_CR21","doi-asserted-by":"crossref","unstructured":"Vaidya, J., Atluri, V., Guo, Q.: The role mining problem: Finding a minimal descriptive set of roles. In: The Twelth ACM Symposium on Access Control Models and Technologies, Sophia Antipolis, France, June 20-22, pp. 175\u2013184 (2007)","DOI":"10.1145\/1266840.1266870"},{"key":"1_CR22","doi-asserted-by":"crossref","unstructured":"Vaidya, J., Atluri, V., Guo, Q., Lu, H.: Edge-rmp: Minimizing administrative assignments for role-based access control. Journal of Computer Security (to appear)","DOI":"10.3233\/JCS-2009-0341"},{"key":"1_CR23","doi-asserted-by":"crossref","unstructured":"Ene, A., Horne, W., Milosavljevic, N., Rao, P., Schreiber, R., Tarjan, R.: Fast exact and heuristic methods for role minimization problems. In: The ACM Symposium on Access Control Models and Technologies (June 2008)","DOI":"10.1145\/1377836.1377838"},{"key":"1_CR24","doi-asserted-by":"crossref","unstructured":"Zhang, B., Al-Shaer, E., Jagadeesan, R., Riely, J., Pitcher, C.: Specifications of a high-level conflict-free firewall policy language for multi-domain networks. In: The Twelth ACM Symposium on Access Control Models and Technologies, pp. 185\u2013194 (2007)","DOI":"10.1145\/1266840.1266871"},{"issue":"3","key":"1_CR25","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/1805974.1805983","volume":"13","author":"J. Vaidya","year":"2010","unstructured":"Vaidya, J., Atluri, V., Guo, Q.: The role mining problem: A formal perspective. ACM Trans. Inf. Syst. Secur.\u00a013(3), 1\u201331 (2010)","journal-title":"ACM Trans. Inf. Syst. Secur."},{"key":"1_CR26","first-page":"21","volume-title":"SACMAT 2008: Proceedings of the 13th ACM Symposium on Access Control Models and Technologies","author":"I. Molloy","year":"2008","unstructured":"Molloy, I., Chen, H., Li, T., Wang, Q., Li, N., Bertino, E., Calo, S., Lobo, J.: Mining roles with semantic meanings. In: SACMAT 2008: Proceedings of the 13th ACM Symposium on Access Control Models and Technologies, pp. 21\u201330. ACM, New York (2008)"},{"key":"1_CR27","doi-asserted-by":"crossref","unstructured":"Colantonio, A., Pietro, R.D., Ocello, A.: Leveraging lattices to improve role mining. In: Proceedings of The IFIP TC-11 23rd International Information Security Conference (IFIP SEC 2008), pp. 333\u2013347 (2008)","DOI":"10.1007\/978-0-387-09699-5_22"},{"key":"1_CR28","doi-asserted-by":"publisher","first-page":"2129","DOI":"10.1145\/1363686.1364198","volume-title":"SAC 2008: Proceedings of the 2008 ACM Symposium on Applied Computing","author":"A. Colantonio","year":"2008","unstructured":"Colantonio, A., Di Pietro, R., Ocello, A.: A cost-driven approach to role engineering. In: SAC 2008: Proceedings of the 2008 ACM Symposium on Applied Computing, pp. 2129\u20132136. ACM, New York (2008)"},{"key":"1_CR29","doi-asserted-by":"crossref","unstructured":"Guo, Q., Vaidya, J., Atluri, V.: The role hierarchy mining problem: Discovery of optimal role hierarchies. In: Proceedings of the 24th Annual Computer Security Applications Conference (December 8-12, 2008)","DOI":"10.1109\/ACSAC.2008.38"},{"key":"1_CR30","series-title":"Lecture Notes in Artificial Intelligence","doi-asserted-by":"publisher","first-page":"278","DOI":"10.1007\/978-3-540-30214-8_22","volume-title":"Discovery Science","author":"F. Geerts","year":"2004","unstructured":"Geerts, F., Goethals, B., Mielikainen, T.: Tiling databases. In: Suzuki, E., Arikawa, S. (eds.) DS 2004. LNCS (LNAI), vol.\u00a03245, pp. 278\u2013289. Springer, Heidelberg (2004)"},{"key":"1_CR31","doi-asserted-by":"crossref","unstructured":"Lu, H., Vaidya, J., Atluri, V.: Optimal boolean matrix decomposition: Application to role engineering. In: IEEE International Conference on Data Engineering (April 2008) (to appear)","DOI":"10.1109\/ICDE.2008.4497438"},{"key":"1_CR32","doi-asserted-by":"publisher","first-page":"299","DOI":"10.1145\/1455770.1455809","volume-title":"CCS 2008: Proceedings of the 15th ACM conference on Computer and Communications Security","author":"M. Frank","year":"2008","unstructured":"Frank, M., Basin, D., Buhmann, J.M.: A class of probabilistic models for role engineering. In: CCS 2008: Proceedings of the 15th ACM conference on Computer and Communications Security, pp. 299\u2013310. ACM, New York (2008)"},{"key":"1_CR33","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"287","DOI":"10.1007\/978-3-540-89862-7_24","volume-title":"Information Systems Security","author":"L. Fuchs","year":"2008","unstructured":"Fuchs, L., Pernul, G.: Hydro - hybrid development of roles. In: Sekar, R., Pujari, A.K. (eds.) ICISS 2008. LNCS, vol.\u00a05352, pp. 287\u2013302. Springer, Heidelberg (2008)"},{"key":"1_CR34","doi-asserted-by":"crossref","unstructured":"Bartal, Y., Mayer, A., Nissim, K., Wool, A.: Firmato: A novel firewall management toolkit. In: IEEE Symposium on Security and Privacy, pp. 17\u201331 (1999)","DOI":"10.1109\/SECPRI.1999.766714"},{"key":"1_CR35","doi-asserted-by":"crossref","unstructured":"Mayer, A.J., Wool, A., Ziskind, E.: Fang: A firewall analysis engine. In: IEEE Symposium on Security and Privacy, pp. 177\u2013187 (2000)","DOI":"10.1109\/SECPRI.2000.848455"},{"key":"1_CR36","doi-asserted-by":"crossref","unstructured":"Hazelhurst, S., Attar, A., Sinnappan, R.: Algorithms for improving the dependability of firewall and filter rule lists. In: International Conference on Dependable Systems and Networks, pp. 576\u2013585 (2000)","DOI":"10.1109\/ICDSN.2000.857593"},{"key":"1_CR37","unstructured":"Yuan, L., Mai, J., Su, Z., Chen, H., Chuah, C., Mohapatra, P.: Fireman: A toolkit for firewall modeling and analysis. In: IEEE Symposium on Security and Privacy, pp. 199\u2013213 (2006)"},{"key":"1_CR38","doi-asserted-by":"crossref","unstructured":"Le, F., Lee, S., Wong, T., Kim, H.S., Newcomb, D.: Minerals: using data mining to detect router misconfigurations. In: SIGCOMM Workshop on Mining Network Data (2006)","DOI":"10.1145\/1162678.1162681"},{"key":"1_CR39","doi-asserted-by":"crossref","unstructured":"Al-Shaer, E.S., Hamed, H.H.: Discovery of policy anomalies in distributed firewalls. In: Annual Joint Conference of the IEEE Computer and Communications Societies (2004)","DOI":"10.1109\/INFCOM.2004.1354680"},{"key":"1_CR40","doi-asserted-by":"publisher","first-page":"1278","DOI":"10.1109\/PROC.1975.9939","volume":"69","author":"J.H. Saltzer","year":"1975","unstructured":"Saltzer, J.H., Schroeder, M.D.: The protection of information in computer systems. Proceeding of the IEEE\u00a069, 1278\u20131308 (1975)","journal-title":"Proceeding of the IEEE"},{"key":"1_CR41","doi-asserted-by":"crossref","unstructured":"Allen, J., Christie, A., Fithen, W., McHugh, J., Pickel, J., Stoner, E.: State of the practice of intrusion detection technologies, cmu\/sei-99-tr-028. Technical report, Carnegie Mellon University (1999)","DOI":"10.21236\/ADA375846"},{"issue":"4","key":"1_CR42","doi-asserted-by":"publisher","first-page":"405","DOI":"10.1016\/0167-4048(93)90029-5","volume":"12","author":"T.F. Lunt","year":"1993","unstructured":"Lunt, T.F.: A survey of intrusion detection techniques. Computers and Security\u00a012(4), 405\u2013418 (1993)","journal-title":"Computers and Security"},{"issue":"3","key":"1_CR43","doi-asserted-by":"publisher","first-page":"295","DOI":"10.1145\/322510.322526","volume":"2","author":"T. Lane","year":"1999","unstructured":"Lane, T., Brodley, C.: Temporal sequence learning and data reduction for anomaly detection. ACM Transations on Information Systems Security\u00a02(3), 295\u2013331 (1999)","journal-title":"ACM Transations on Information Systems Security"}],"container-title":["Lecture Notes in Computer Science","Advances in Information and Computer Security"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-16825-3_1","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,6,6]],"date-time":"2019-06-06T00:59:56Z","timestamp":1559782796000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-16825-3_1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2010]]},"ISBN":["9783642168246","9783642168253"],"references-count":43,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-16825-3_1","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2010]]}}}