paper-with-me

홈 › Papers

Using Constraint Programming and Graph Representation Learning for Generating Interpretable Cloud Security Policies

2022-05-02 · Mikhail Kazdagli, Mohit Tiwari, Akshat Kumar

Modern software systems rely on mining insights from business sensitive data stored in public clouds. A data breach usually incurs significant (monetary) loss for a commercial organization. Conceptually, cloud security heavily relies on Identity Access Management (IAM) policies that IT admins need to properly configure and periodically update. Security negligence and human errors often lead to misconfiguring IAM policies which may open a backdoor for attackers. To address these challenges, first, we develop a novel framework that encodes generating optimal IAM policies using constraint programming (CP). We identify reducing dark permissions of cloud users as an optimality criterion, which intuitively implies minimizing unnecessary datastore access permissions. Second, to make IAM policies interpretable, we use graph representation learning applied to historical access patterns of users to augment our CP model with similarity constraints: similar users should be grouped together and share common IAM policies. Third, we describe multiple attack models and show that our optimized IAM policies significantly reduce the impact of security attacks using real data from 8 commercial organizations, and synthetic instances.

📄 PDF Abstract BibTeX arXiv:2205.01240

Code (1)

mikhail247/iamax 공식 구현

Tasks

Graph Representation LearningManagementRepresentation Learning

Similar Papers 제목 키워드 기반

Deep Descriptive Clustering

2021-05-24 · Hongjing Zhang, Ian Davidson

Recent work on explainable clustering allows describing clusters when the features are interpretable. However, much modern machine learning focuses on complex data such as images, text, and graphs where deep learning is …

ClusteringDescriptiveRepresentation Learning

Rule Induction in Knowledge Graphs Using Linear Programming

2021-10-15 · Sanjeeb Dash, Joao Goncalves

We present a simple linear programming (LP) based method to learn compact and interpretable sets of rules encoding the facts in a knowledge graph (KG) and use these rules to solve the KG completion problem. Our LP model …

Knowledge Graphs

GDLNN: Marriage of Programming Language and Neural Networks for Accurate and Easy-to-Explain Graph Classification

2025-10-01 · Minseok Jeon, Seunghyun Park arxiv

We present GDLNN, a new graph machine learning architecture, for graph classification tasks. GDLNN combines a domain-specific programming language, called GDL, with neural networks. The main strength of GDLNN lies in its…

Graph ClassificationGraph Learning

Balancing multiscale similarity and cartographic constraints: A similarity-driven optimization framework for line generalization

2026-07-28 · Pengbo Li, Haowen Yan, Xiaomin Lu, Binbin Lin arxiv

Cartographic generalization is essential for generating multiscale map representations by balancing information preservation and cartographic readability. However, automated generalization remains challenging because exi…

Learning Interpretable Error Functions for Combinatorial Optimization Problem Modeling

2020-02-23 · Florian Richoux, Jean-François Baffier

In Constraint Programming, constraints are usually represented as predicates allowing or forbidding combinations of values. However, some algorithms exploit a finer representation: error functions. Their usage comes with…

Combinatorial Optimizationvalid