发明名称 Role mining with user attribution using generative models
摘要 Applications of machine learning techniques such as Latent Dirichlet Allocation (LDA) and author-topic models (ATM) to the problems of mining of user roles to specify access control policies from entitlement as well as logs which contain record of the usage of these entitlements are provided. In one aspect, a method for performing role mining given a plurality of users and a plurality of permissions is provided. The method includes the following steps. At least one generative machine learning technique, e.g., LDA, is used to obtain a probability distribution θ for user-to-role assignments and a probability distribution β for role-to-permission assignments. The probability distribution θ for user-to-role assignments and the probability distribution β for role-to-permission assignments are used to produce a final set of roles, including user-to-role assignments and role-to-permission assignments.
申请公布号 US8983877(B2) 申请公布日期 2015.03.17
申请号 US201213411174 申请日期 2012.03.02
申请人 International Business Machines Corporation 发明人 Chari Suresh N.;Molloy Ian Michael;Park Youngja
分类号 G06N5/00;G06F1/00;G06N99/00;G06F21/60 主分类号 G06N5/00
代理机构 Michael J. Chang, LLC 代理人 Dougherty Anne V.;Michael J. Chang, LLC
主权项 1. A method for performing role mining given a plurality of users and a plurality of permissions, the method comprising the steps of: using at least one generative machine learning technique to obtain a collection K of k roles, a probability distribution θ for user-to-role assignments and a probability distribution β for role-to-permission assignments, wherein the probability distribution θ for user-to-role assignments and the probability distribution β for role-to-permission assignments account for past usage of permission assignments by the users; and finding latent roles in the permissions by converting the probability distribution θ for user-to-role assignments and the probability distribution β for role-to-permission assignments into a final set of roles, including discrete user-to-role assignments and role-to-permission assignments.
地址 Armonk NY US