Transaction Logs in Access Control: Leveraging an Under-Utilized Data Source


연구 분야: Software Development



학회: IFIP Annual Conference on Data and Applications Security and Privacy


초록

Maintaining access control policies is an ongoing process to ensure required but not excessive authorizations. Organizations thus leverage various data sources to ease this maintenance. Among these data sources are access control matrices, attributes, access logs, and transaction logs. While research reasonably covers the former data sources, the potential of transaction logs remains untapped. We pave the way for transaction logs as a data source in access control by (i) expressing them with a formalization, (ii) pinpointing them in typical Identity and Access Management (IAM) infrastructures, and (iii) grounding them in IAM processes. We conclude that access control transaction logs are valuable data sources for improving analytical capabilities for IAM.


Author Profile
Sascha Kern

Nexis GmbH Rudolf-Vogt-Straße 6 93053 Regensburg Germany

Germany
Author Profile
Thomas Baumer

Nexis GmbH Rudolf-Vogt-Straße 6 93053 Regensburg Germany

Germany
Author Profile
Raphael Neudert

Nexis GmbH Rudolf-Vogt-Straße 6 93053 Regensburg Germany

Germany

📄 논문 정보

발행 연도 2025년
인용수 0
출판 국가 Germany
사이트 Springer
좋아요 수 0

연관 논문 목록 (162건)