首页> 外文会议>2nd workshop on assurable and usable security configuration 2009 >Security Policy Refinement using Data Integration: A Position Paper
【24h】

Security Policy Refinement using Data Integration: A Position Paper

机译:使用数据集成细化安全策略:立场文件

获取原文
获取原文并翻译 | 示例

摘要

In spite of the wide adoption of policy-based approaches for security management, and many existing treatments of policy verification and analysis, relatively little attention has been paid to policy refinement: the problem of deriving lower-level, runnable policies from higher-level policies, policy goals, and specifications. In this paper we present our initial ideas on this task, using and adapting concepts from data integration. We take a view of policies as governing the performance of an action on a target by a subject, possibly with certain conditions. Transformation rules are applied to these components of a policy in a structured way, in order to translate the policy into more refined terms; the transformation rules we use are similar to those of 'global-as-view' database schema mappings, or to extensions thereof. We illustrate our ideas with an example.
机译:尽管安全性管理已广泛采用基于策略的方法,并且对策略验证和分析进行了许多现有的处理,但对策略改进的关注却相对较少:从较高级别的策略派生出较低级别的可运行策略的问题,政策目标和规范。在本文中,我们提出了关于此任务的初步构想,使用并改编了数据集成中的概念。我们认为政策可能会在一定条件下控制主体对目标执行某项操作。转换规则以结构化的方式应用于策略的这些组成部分,以便将策略转换为更精细的术语。我们使用的转换规则与“全局视图”数据库模式映射或其扩展类似。我们通过一个例子来说明我们的想法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号