Visible to the public Proposed Model for Natural Language ABAC Authoring

TitleProposed Model for Natural Language ABAC Authoring
Publication TypeConference Paper
Year of Publication2017
AuthorsTurner, Ronald C.
Conference NameProceedings of the 2Nd ACM Workshop on Attribute-Based Access Control
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-4910-9
KeywordsABAC, business rules, Collaboration, natural language policies, policy, Policy Based Governance, policy semantics, policy-based governance, pubcrawl, RDF analytics, SPARQL queries, XACML authoring tool
Abstract

Authorization policy authoring has required tools from the start. With access policy governance now an executive-level responsibility, it is imperative that such a tool expose the policy to business users' with little or no IT intervention-as natural language. NIST SP 800-162 [1] first prescribes natural language policies (NLPs) as the preferred expression of policy and then implicitly calls for automated translation of NLP to machine-executable code. This paper therefore proposes an interoperable model for the NLP's human expression. It furthermore documents the research and development of a tool set for end-to-end authoring and translation. This R&D journey-focusing constantly on end users' has debunked certain myths, has responded to steadily increasing market sophistication, has applied formal disciplines (e.g. ontologies, grammars and compiler design) and has motivated an informal demonstration of autonomic code generation. The lessons learned should be of practical value to the entire ABAC community. The research in progress' increasingly complex policies, proactive rule analytics, and expanded NLP authoring language support will require collaboration with an ever-expanding technical community from industry and academia.

URLhttps://dl.acm.org/doi/10.1145/3041048.3041054
DOI10.1145/3041048.3041054
Citation Keyturner_proposed_2017