Access Policy Prediction via User Behavior
摘要
Organizations use Role-based access controls (RBACs) and Attribute-based access controls (ABACs) to manage permissions, ensuring sensitive information is protected from junior staff. This management becomes complex in larger organizations with frequent role changes and diverse projects. This paper investigates using historical access data to authorize new requests, whether from existing users needing access to new resources, new users requesting established resources, or existing users seeking broader access. We propose a model based on hierarchical clustering and evaluate it using an ABAC audit dataset.