Users tracking and roles mining in web-based applications

  • Authors:
  • Yaron Gonen;Ehud Gudes

  • Affiliations:
  • Ben-Gurion University of the Negev, Be'er Sheva, Israel;-

  • Venue:
  • Proceedings of the 2011 Joint EDBT/ICDT Ph.D. Workshop
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

When a database is accessed via a web application, web-users are not connect directly to the database, but rather via the web application. From a database point of view, such a connection is always established by the same db-user (i.e. the web application's db-user) and specific data on the web-user is not available to the database. As a consequence, web-users' specific data cannot be audited and fine-grained access control cannot be implemented. We propose a method that provide the ability to track the web-users in web databases. The new method can be applied to legacy web applications without requiring any changes in their existing infrastructure. Using the tracked database, we propose a method to identify logical sessions (business logic), which we will use to mine the true users-roles of the web application.