遇见数据集

Graph-based ABAC — Experimental Dataset (v1)

收藏
Zenodo2026-05-16 更新2026-05-26 收录
官方服务:

资源简介:

Companion data for the manuscript "Modeling, Enforcement, and Analysis of ABAC Policies Using a Graph-based Framework" by Mian Yang, Vijayalakshmi Atluri, Shamik Sural, and Jaideep Vaidya. Manuscript submitted. Corresponding author: Mian Yang (mian.yang@rutgers.edu). This work extends the published conference version: Yang, M., Atluri, V., Sural, S., and Vaidya, J. (2024). A Graph-based Framework for ABAC Policy Enforcement and Analysis. In: Data and Applications Security and Privacy XXXVIII (DBSec 2024), Springer, pp. 3–23. The notebooks that generated and consumed this data are in the companion GitHub repository: https://github.com/mianyacd/graph-abac FOLDER TO PAPER FIGURE MAPPING • perf_loop_apoc_time_likeold_results_classified/ — Figure 2(a) (mean latency by decision outcome vs |U|) and Figure 3 (execution time vs rule size at |U_C|=600). Contains per-config CSVs plus the aggregated _ALLDBS_THREE_BUCKETS file with PERMIT / DENY-matched / no-rule-found buckets. • perf_usercentric_stepwise_results_Sept11/ — Figure 5 (user-centric analysis time vs |U|) and Figure 6 (vs |U_C|). Stepwise per-user measurements per config plus the aggregated _SUMMARY_USERCENTRIC_STEPWISE_SAMPLE file. Largest folder (~285 MB). • generated_rules_deny_pct20/, generated_rules_deny_pct40/, generated_rules_deny_pct60/ — Figure 2(b) (deny-rate sweep at three coverage levels). Each contains rule definitions plus perf_access_eval_deny_pct/_SUMMARY_DENY_PCT execution results. • deny_vs_time_by_coverage_combined.csv — Figure 2(b) combined tidy form read by the plotting notebook. • UC50_generated_rules_deny_pct20/, UC50_generated_rules_deny_pct50/ — Figure 4 and Figure 7 input rule definitions for the |U_C|=50 deny-ratio comparison. Generated by 02_generate_rules_by_deny_pct.ipynb with seed 20250830. WHAT IS NOT IN THIS ARCHIVE • Final figure PDFs/PNGs and the plotting scripts live in the companion GitHub repo (figures/ and notebooks/04_plots_for_paper.ipynb). • The 2.7 GB generated_rules/ folder is omitted because it is deterministically regenerable by running 01_generate_rules.ipynb with seed 123. • conflict_runs/, redundancy_runs/, and request_conflict_runs/ (backing Figures 8a–c) are included in full in the GitHub repo under data_samples/conflict_redundancy/ (~3 MB combined). They are not duplicated here. • Several iterative perf_* folders (perf_results/, perf_loop_results/, perf_loop_apoc_results/, perf_loop_apoc_likeold_results/, perf_loop_apoc_time_likeold_results/, perf_usercentric_stepwise_results/) were earlier methodological iterations during development. None of them feed a figure in the final paper. • Figure 4 and Figure 7 per-configuration execution results were not persisted to disk during the paper's evaluation runs — only the rule-set inputs (the UC50_* folders above) and the final figure PDFs are kept. The results can be regenerated by running the user-centric and access-request benchmarking cells in notebooks/03_neo4j_write_and_query.ipynb against the included UC50_* rule files. HOW THE DATA WAS PRODUCED Every rule set in this archive was generated by Python scripts with fixed random seeds — there is no real-world or personally identifiable data. The synthesis procedure and seeds are documented in 01_generate_rules.ipynb (seed 123) and 02_generate_rules_by_deny_pct.ipynb (seed 20250830) in the GitHub repo. Execution results were collected by running the queries in 03_neo4j_write_and_query.ipynb against a local Neo4j 5.x instance with the APOC plugin. LICENSE Creative Commons Attribution 4.0 International (CC-BY-4.0). CITATION @dataset{yang2026graphabac_data, author = {Yang, Mian and Atluri, Vijayalakshmi and Sural, Shamik and Vaidya, Jaideep}, title = {Graph-based ABAC --- Experimental Dataset (v1)}, year = {2026}, publisher = {Zenodo}, doi = {10.5281/zenodo.20215538}, url = {https://doi.org/10.5281/zenodo.20215538}}

提供机构:
Zenodo
创建时间:
2026-05-15
二维码
社区交流群
二维码
科研交流群
商业服务