首页> 外文会议>2013 IEEE Conference on Communications and Network Security >A specification method for analyzing fine grained network security mechanism configurations
【24h】

A specification method for analyzing fine grained network security mechanism configurations

机译:一种分析细粒度网络安全机制配置的规范方法

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

Quick evolution, heterogeneity, interdependence between equipment, and many other factors induce high complexity to network security analysis. Although several approaches have proposed different analysis tools, achieving this task requires experienced and proficient security administrators who can handle all these parameters. The challenge is not to propose a temporary solution but to offer a building block for this large domain, though no approach can be optimal for all tasks. In previous papers, we have proposed a novel formal model of equipment configuration built on data flow attribute-based approach to detect network security conflicts. In this paper, we extend the previous proposed model in order to make it more generic by proving it can handle microscopic analysis. We define a formal analysis method for network security mechanisms. Therefore, we specify our approach in Colored Petri Networks to automate the conflicts analysis and test it on a fine-grained firewall scenario.
机译:快速发展,异构性,设备之间的相互依赖性以及许多其他因素导致网络安全分析的高度复杂性。尽管几种方法提出了不同的分析工具,但是要实现此任务,需要经验丰富且精通的安全管理员,他们可以处理所有这些参数。面临的挑战不是提出一个临时解决方案,而是为这个大领域提供一个构建块,尽管没有一种方法可以对所有任务都是最优的。在先前的论文中,我们提出了一种新颖的设备配置正式模型,该模型基于基于数据流属性的方法来检测网络安全冲突。在本文中,我们扩展了先前提出的模型,以通过证明它可以处理微观分析来使其更通用。我们为网络安全机制定义了一种形式化的分析方法。因此,我们在有色Petri网络中指定了我们的方法来自动进行冲突分析,并在细粒度的防火墙方案中对其进行测试。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号