題名: | Network Security Management with SecurityPolicies |
作者: | Sivasubramanian, Vinoth |
期刊名/會議名稱: | 2008 ICS會議 |
摘要: | A key issue in network security management is how to define a formal security policy. A good policy specification should be easy to get right and relatively stable, even in a dynamically changing network. Much work has been done in automating network security management. But the policy languages used are usually operational and do not explicitly express the underlying security goal. We propose an approach where policy is defined as statements of desired security properties, whose compliance can be checked automatically by analyzing the configuration of the network. We use a simple policy model, the data access-control list (DACL) to demonstrate this idea. We present a framework and corresponding algorithms for checking that low-level configurations altogether uphold the highlevel DACL policy, taking into consideration potential software vulnerabilities. |
日期: | 2009-02-10T06:38:10Z |
分類: | 2008年 ICS 國際計算機會議 |
文件中的檔案:
檔案 | 描述 | 大小 | 格式 | |
---|---|---|---|---|
ce07ics002008000079.pdf | 138.53 kB | Adobe PDF | 檢視/開啟 |
在 DSpace 系統中的文件,除了特別指名其著作權條款之外,均受到著作權保護,並且保留所有的權利。