首页> 外文会议>IFIP TC 11 International conference on information security and privacy >Model-Driven Integration and Analysis of Access-control Policies in Multi-layer Information Systems
【24h】

Model-Driven Integration and Analysis of Access-control Policies in Multi-layer Information Systems

机译:多层信息系统中访问控制策略的模型驱动集成与分析

获取原文

摘要

Security is a critical concern for any information system. Security properties such as confidentiality, integrity and availability need to be enforced in order to make systems safe. In complex environments, where information systems are composed of a number of heterogeneous subsystems, each must participate in their achievement. Therefore, security integration mechanisms are needed in order to 1) achieve the global security goal and 2) facilitate the analysis of the security status of the whole system. For the specific case of access-control, access-control policies may be found in several components (databases, networks and applications) all, supposedly, working together in order to meet the high level security property. In this work we propose an integration mechanism for access-control policies to enable the analysis of the system security. We rely on model-driven technologies and the XACML standard to achieve this goal.
机译:安全性是任何信息系统的关键问题。需要强制执行安全性,例如机密性,完整性和可用性,以便使系统安全。在复杂的环境中,信息系统由许多异构子系统组成,每个系统必须参与其成就。因此,需要安全集成机制到1)实现全局安全目标,2)促进整个系统的安全状态的分析。对于访问控制的特定情况,可以在几个组件(数据库,网络和应用程序)中找到访问控制策略,据称,一起工作以符合高级安全性。在这项工作中,我们提出了一个用于访问控制策略的集成机制,以实现系统安全性的分析。我们依靠模型驱动的技术和XACML标准来实现这一目标。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号