An Information Visualization Software System to Manage Resource Access Control Policies Jaime Montemayor, Inventor Thomas Llanso, Inventor
Problem Background Complex digital Access Control policies/ rules can be difficult to author, analyze, update, approve, and reverse-engineer. –Access can be a function of many factors –Visualization techniques can help manage complex rule sets Security clearance Physical location Type of workstation Type of user login Role / Group Time of day Operational Need Security Risk
Access Visualization Tool (“Ruba”) Visualize policies from many angles Reveal hidden relationships, interactions Useful for experts and non-experts alike
Groups and Hierarchy Different Views Answer Different Questions
Access Control Matrix Different Views Answer Different Questions
Incremental Exploration Different Views Answer Different Questions
Technical Applicability Useful anywhere control access required –Networks, virtual networks –Web sites, portals, web services, messaging –Databases, directories, other repositories Useful to different stakeholders –Network, repository, mission owners –System support personnel –System Certifiers –System and Network Accreditors
Commercial Applicability Relevant across many industries –Government / Military –Medical –Financial –Legal –Entertainment Can play a role in meeting the spirit of security-related legislation –HIPAA –Graham Leach Bliley Act
Commercial Opportunities For technical information contact: Jaime Montemayor, Inventor Thomas Llanso, Inventor For licensing information contact: Norma Lee Todd, Technology Manager Office of Technology Transfer The Johns Hopkins University Applied Physics Laboratory Johns Hopkins Road Laurel, MD