首页> 外文会议>Industrial Informatics, 2004. INDIN '04. 2004 2nd IEEE International Conference on >Security service adaptation for embedded service systems in changing environments
【24h】

Security service adaptation for embedded service systems in changing environments

机译:不断变化的环境中针对嵌入式服务系统的安全服务调整

获取原文

摘要

Distributed embedded applications increasingly operate in changing environments where the application security depends on the type and properties of the currently used communication services and employed devices. While vulnerabilities, threats, and available security function processing power are changing, the applications, however, should automatically adapt to the varying conditions in order to maintain the necessary security without endeavor of users. We report on the security management subproject of the SIRENA project where we apply a special combination of policy-based management with model-based management in order to support fully automated security management functions at runtime as well as tool-assisted security requirement definition and system design. Within an application model, the definition of the application's high-level security policy is of special importance. It represents the abstract security requirements and forms the starting point for the automated derivation of suitable security subsystem configurations which enforce the policy under changing environment conditions. The abstract policy representation relies on the generalized role based access control model (GRBAC).
机译:分布式嵌入式应用程序越来越多地在不断变化的环境中运行,在这些环境中,应用程序安全性取决于当前使用的通信服务和使用的设备的类型和属性。当漏洞,威胁和可用的安全功能处理能力在变化时,应用程序应自动适应各种条件,以保持必要的安全性而无需用户的努力。我们报告SIRENA项目的安全管理子项目,在该项目中,我们将基于策略的管理与基于模型的管理进行了特殊组合,以便在运行时支持全自动安全管理功能以及工具辅助的安全需求定义和系统设计。在应用程序模型中,应用程序的高级安全策略的定义特别重要。它代表了抽象的安全性要求,并构成了自动派生合适的安全子系统配置的起点,这些子系统在变化的环境条件下强制执行该策略。抽象策略表示依赖于基于通用角色的访问控制模型(GRBAC)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号