Network-Level Access Control Policy Analysis and Transformation

Network-Level Access Control Policy Analysis and Transformation
复制标题

网络级访问控制策略分析与改造

DOI:
--
复制
发表时间:
2012
期刊:
IEEE/ACM Transactions on Networking
影响因子:
--
通讯作者:
A. Lioy
A. Lioy
中科院分区:
--
文献类型:
--
作者:
C. Basile;Alberto Cappadonia;A. Lioy

文献摘要

被引文献

相似文献

网络级访问控制策略通常由不同的人(网络、应用程序和安全管理员)指定,这可能会导致冲突或次优策略。我们已经定义了一个新的正式模型的政策表示,是独立的实际执行的元素,沿着的程序,可以很容易地识别和删除的不一致和异常。此外,可以将策略转换为目标访问控制元素所使用的模型,以便为实际部署做好准备。特别是,我们表明,每一个政策都可以转化为一个使用“第一匹配规则”的决议策略。我们的政策模型和优化过程已实施的工具,实验证明其适用于现实生活中的情况。
Network-level access control policies are often specified by various people (network, application, and security administrators), and this may result in conflicts or suboptimal policies. We have defined a new formal model for policy representation that is independent of the actual enforcement elements, along with a procedure that allows the easy identification and removal of inconsistencies and anomalies. Additionally, the policy can be translated to the model used by the target access control element to prepare it for actual deployment. In particular, we show that every policy can be translated into one that uses the “First Matching Rule” resolution strategy. Our policy model and optimization procedure have been implemented in a tool that experimentally demonstrates its applicability to real-life cases.