Evidence-based role based access control

    公开(公告)号:US10171471B2

    公开(公告)日:2019-01-01

    申请号:US14991958

    申请日:2016-01-10

    IPC分类号: G06F21/00 H04L29/06 G06N99/00

    摘要: Methods, computing systems and computer program products implement embodiments of the present invention that include assigning, to multiple users, respective sets of original roles for accessing data stored on a computer system, and performing, in response to requests from the users, multiple operations on the data. While performing the multiple operations on the data, a transaction log is generated that includes a plurality of entries, each of the entries storing attributes of a given operation. Based on the entries in the log file, a respective set of learned roles for respective users is identified, and the respective sets of the learned roles are assigned to the respective users.