Proposed Model for Natural Language ABAC Authoring
Title | Proposed Model for Natural Language ABAC Authoring |
Publication Type | Conference Paper |
Year of Publication | 2017 |
Authors | Turner, Ronald C. |
Conference Name | Proceedings of the 2Nd ACM Workshop on Attribute-Based Access Control |
Publisher | ACM |
Conference Location | New York, NY, USA |
ISBN Number | 978-1-4503-4910-9 |
Keywords | ABAC, business rules, Collaboration, natural language policies, policy, Policy Based Governance, policy semantics, policy-based governance, pubcrawl, RDF analytics, SPARQL queries, XACML authoring tool |
Abstract | Authorization policy authoring has required tools from the start. With access policy governance now an executive-level responsibility, it is imperative that such a tool expose the policy to business users' with little or no IT intervention-as natural language. NIST SP 800-162 [1] first prescribes natural language policies (NLPs) as the preferred expression of policy and then implicitly calls for automated translation of NLP to machine-executable code. This paper therefore proposes an interoperable model for the NLP's human expression. It furthermore documents the research and development of a tool set for end-to-end authoring and translation. This R&D journey-focusing constantly on end users' has debunked certain myths, has responded to steadily increasing market sophistication, has applied formal disciplines (e.g. ontologies, grammars and compiler design) and has motivated an informal demonstration of autonomic code generation. The lessons learned should be of practical value to the entire ABAC community. The research in progress' increasingly complex policies, proactive rule analytics, and expanded NLP authoring language support will require collaboration with an ever-expanding technical community from industry and academia. |
URL | https://dl.acm.org/doi/10.1145/3041048.3041054 |
DOI | 10.1145/3041048.3041054 |
Citation Key | turner_proposed_2017 |