{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T15:27:02Z","timestamp":1785511622092,"version":"3.56.0"},"publisher-location":"New York, NY, USA","reference-count":35,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,8,29]],"date-time":"2023-08-29T00:00:00Z","timestamp":1693267200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,8,29]]},"DOI":"10.1145\/3600160.3604988","type":"proceedings-article","created":{"date-parts":[[2023,8,9]],"date-time":"2023-08-09T22:54:41Z","timestamp":1691621681000},"page":"1-10","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":6,"title":["Mitigating Privilege Misuse in Access Control through Anomaly Detection"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0007-9163-1279","authenticated-orcid":false,"given":"Gelareh","family":"Hasel Mehri","sequence":"first","affiliation":[{"name":"Mathematics &amp; Computer Science, Eindhoven University of Technology, Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-4683-2653","authenticated-orcid":false,"given":"Inez L.","family":"Wester","sequence":"additional","affiliation":[{"name":"Mathematics &amp; Computer Science, Eindhoven University of Technology, Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3122-0236","authenticated-orcid":false,"given":"Federica","family":"Paci","sequence":"additional","affiliation":[{"name":"University of Verona, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9081-5996","authenticated-orcid":false,"given":"Nicola","family":"Zannone","sequence":"additional","affiliation":[{"name":"Mathematics &amp; Computer Science, Eindhoven University of Technology, Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,8,29]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"crossref","unstructured":"A. Abu\u00a0Jabal E. Bertino J. Lobo M. Law A. Russo S. Calo and D. Verma. 2020. Polisma - A Framework for Learning Attribute-Based Access Control Policies. In ESORICS. Springer 523\u2013544.","DOI":"10.1007\/978-3-030-58951-6_26"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"crossref","unstructured":"M. Alizadeh S. Peters S. Etalle and N. Zannone. 2018. Behavior analysis in the medical sector: theory and practice. In SAC. ACM 1637\u20131646.","DOI":"10.1145\/3167132.3167307"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"crossref","unstructured":"L. Argento A. Margheri F. Paci V. Sassone and N. Zannone. 2018. Towards Adaptive Access Control. In DBSec. Springer 99\u2013109.","DOI":"10.1007\/978-3-319-95729-6_7"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2013.08.001"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"crossref","unstructured":"B. Biggio I. Pillai S. Rota\u00a0Bul\u00f2 D. Ariu M. Pelillo and F. Roli. 2013. Is Data Clustering in Adversarial Settings Secure?. In AISec. ACM 87\u201398.","DOI":"10.1145\/2517312.2517321"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"crossref","unstructured":"T. Bui and S. Stoller. 2020. A Decision Tree Learning Approach for Mining Relationship-Based Access Control Policies. In SACMAT. ACM 167\u2013178.","DOI":"10.1145\/3381991.3395619"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"crossref","unstructured":"L. Cappelletti S. Valtolina G. Valentini M. Mesiti and E. Bertino. 2019. On the Quality of Classification Models for Inferring ABAC Policies from Access Logs. In Big Data. IEEE 4000\u20134007.","DOI":"10.1109\/BigData47090.2019.9005959"},{"key":"e_1_3_2_1_8_1","volume-title":"Conference on Artificial Intelligence. AAAI Press, 6930\u20136938","author":"Chakraborty S.","unstructured":"S. Chakraborty, D. Paul, and S. Das. 2021. Automated Clustering of High-dimensional Data with a Feature Weighted Mean Shift Algorithm. In Conference on Artificial Intelligence. AAAI Press, 6930\u20136938."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.compeleceng.2013.11.024"},{"key":"e_1_3_2_1_10_1","unstructured":"C. Chin-Chen L. Iuon-Chang and L. Chia-Te. 2006. An Access Control System with Time-constraint Using Support Vector Machines. Int. J. Secur. Netw. 2 (2006)."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/34.1000236"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1002\/spe.513"},{"key":"e_1_3_2_1_13_1","unstructured":"NJ de Vos. 2015\u20132021. kmodes categorical clustering library. https:\/\/github.com\/nicodv\/kmodes."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"crossref","unstructured":"P Duessel S Luo U Flegel S Dietrich and M Meier. 2020. Tracing Privilege Misuse Through Behavioral Anomaly Detection in Geometric Spaces. In SADFE.","DOI":"10.1109\/SADFE51007.2020.00012"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11235-018-0475-8"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.2307\/2528823"},{"key":"e_1_3_2_1_17_1","volume-title":"PAMMELA: Policy Administration Methodology using Machine Learning. CoRR","author":"Gumma V.","year":"2021","unstructured":"V. Gumma, B. Mitra, S. Dey, P. Patel, S. Suman, and S. Das. 2021. PAMMELA: Policy Administration Methodology using Machine Learning. CoRR (2021)."},{"key":"e_1_3_2_1_18_1","volume-title":"An improved k-prototypes clustering algorithm for mixed numeric and categorical data. Neurocomputing 120","author":"Ji J","year":"2013","unstructured":"J Ji, T Bai, C Zhou, C Ma, and Z Wang. 2013. An improved k-prototypes clustering algorithm for mixed numeric and categorical data. Neurocomputing 120 (2013)."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"crossref","unstructured":"L. Karimi M. Aldairi J. Joshi and M. Abdelhakim. 2022. An Automatic Attribute-Based Access Control Policy Extraction From Access Logs. TDSC 19 4 (2022).","DOI":"10.1109\/TDSC.2021.3054331"},{"key":"e_1_3_2_1_20_1","volume-title":"Big Data","author":"Karimi L","unstructured":"L Karimi and J Joshi. 2018. An Unsupervised Learning Based Approach for Mining Attribute Based Access Control Policies. In Big Data. IEEE, 1427\u20131436."},{"key":"e_1_3_2_1_21_1","volume-title":"DBSCAN: Past, present and future","author":"Khan K","year":"2014","unstructured":"K Khan, SU Rehman, K Aziz, S Fong, and S Sarasvady. 2014. DBSCAN: Past, present and future. In ICADIWT. IEEE, 232\u2013238."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"crossref","unstructured":"P. Legg O. Buckley M. Goldsmith and S. Creese. 2015. Caught in the act of an insider attack: Detection and assessment of insider threat. In HST. IEEE 1\u20136.","DOI":"10.1109\/THS.2015.7446229"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1016\/S0031-3203(02)00060-2"},{"key":"e_1_3_2_1_24_1","volume-title":"Efficient Access Control Permission Decision Engine Based on Machine Learning. Secur Comm Netw","author":"Nicopolitidis P","year":"2021","unstructured":"P Nicopolitidis, A Liu, X Du, and N Wang. 2021. Efficient Access Control Permission Decision Engine Based on Machine Learning. Secur Comm Netw (2021)."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"crossref","unstructured":"M Nobi R Krishnan Y Huang M Shakarami and R Sandhu. 2022. Toward Deep Learning Based Access Control. In CODASPY. ACM 143\u2013\u2013154.","DOI":"10.1145\/3508398.3511497"},{"key":"e_1_3_2_1_26_1","volume-title":"Role-based profile analysis for scalable and accurate insider-anomaly detection","author":"Park J","unstructured":"J Park and J Giordano. 2006. Role-based profile analysis for scalable and accurate insider-anomaly detection. In IPCCC. IEEE, 463\u2013470."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"crossref","unstructured":"T Rashid I Agrafiotis and J Nurse. 2016. A New Take on Detecting Insider Threats: Exploring the Use of Hidden Markov Models. In MIST. 47\u201356.","DOI":"10.1145\/2995959.2995964"},{"key":"e_1_3_2_1_28_1","volume-title":"Modern Approaches in Machine Learning and Cognitive Science: A Walkthrough","author":"Srivastava K","unstructured":"K Srivastava and N Shekokar. 2020. Machine Learning Based Risk-Adaptive Access Control System to Identify Genuineness of the Requester. In Modern Approaches in Machine Learning and Cognitive Science: A Walkthrough. Springer."},{"key":"e_1_3_2_1_29_1","volume-title":"ICVEE, Vol.\u00a0336","author":"Syakur MA","unstructured":"MA Syakur, BK Khotimah, EMS Rochman, and BD Satoto. 2018. Integration k-means clustering method and elbow method for identification of the best customer profile cluster. In ICVEE, Vol.\u00a0336. IOP Publishing."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"crossref","unstructured":"Q Tasali N Gyawali and E Vasserman. 2020. Time Series Anomaly Detection in Medical Break-the-Glass. In HotSoS. ACM.","DOI":"10.1145\/3384217.3386397"},{"key":"e_1_3_2_1_31_1","volume-title":"The Anomaly Detection by Using DBSCAN Clustering with Multiple Parameters","author":"Thang T\u00a0M","unstructured":"T\u00a0M Thang and J Kim. 2011. The Anomaly Detection by Using DBSCAN Clustering with Multiple Parameters. In ICISA. IEEE, 1\u20135."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2017.01.009"},{"key":"e_1_3_2_1_33_1","volume-title":"Role Mining with Missing Values","author":"Vavilis S","unstructured":"S Vavilis, A\u00a0Ionut Egner, M Petkovic, and N Zannone. 2016. Role Mining with Missing Values. In ARES. IEEE, 167\u2013176."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"crossref","unstructured":"Verizon. 2021. Data Breach Investigations Report.","DOI":"10.1016\/S1361-3723(21)00061-0"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"crossref","unstructured":"C. Xiang Y. Wu B. Shen M. Shen H. Huang T. Xu Y. Zhou X. Moore C.and\u00a0Jin and T. Sheng. 2019. Towards Continuous Access Control Validation and Forensics. In CCS. ACM 113\u2013129.","DOI":"10.1145\/3319535.3363191"}],"event":{"name":"ARES 2023: The 18th International Conference on Availability, Reliability and Security","location":"Benevento Italy","acronym":"ARES 2023"},"container-title":["Proceedings of the 18th International Conference on Availability, Reliability and Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3600160.3604988","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3600160.3604988","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:36:13Z","timestamp":1750178173000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3600160.3604988"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,8,29]]},"references-count":35,"alternative-id":["10.1145\/3600160.3604988","10.1145\/3600160"],"URL":"https:\/\/doi.org\/10.1145\/3600160.3604988","relation":{},"subject":[],"published":{"date-parts":[[2023,8,29]]},"assertion":[{"value":"2023-08-29","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}