首页> 外文会议>IEEE Symposium Series on Computational Intelligence >HERMES: A high-level policy language for high-granularity enterprise-wide secure browser configuration management
【24h】

HERMES: A high-level policy language for high-granularity enterprise-wide secure browser configuration management

机译:HERMES:一种用于高粒度企业范围安全浏览器配置管理的高级策略语言

获取原文

摘要

In this article, we describe the characteristics, structure, and uses of HERMES. HERMES is a high-level security policy description language. Its characteristics are: (1) enable the specification of organizational domain knowledge in a hierarchical manner; (2) enable the specification of security policies at desired granularity levels within the organizational IT and OT infrastructure; (3) enable security policies to be automatically instantiated into security configurations; (4) it is human-centered and designed for ease of use; (5) it is application and device independent. We show an example of using HERMES to write a high-level policy and show examples of how such policy can be instantiated into a domain and device, user and role, application and action specific security configuration. We also describe the integration of HERMES within the HiFiPol:Browser policy management system. We believe HERMES is a necessary step toward securing the client side of the web ecosystem and prevent or mitigate the current onslaught of web browser-based attacks, such as phishing.
机译:在本文中,我们描述了爱马仕的特征,结构和使用。爱马仕是一个高级安全策略描述语言。其特征是:(1)以分层方式启用组织域知识的规范; (2)在组织IT和OT基础设施中,可以在所需的粒度水平上规范安全策略; (3)启用安全策略要自动实例化为安全配置; (4)它是以人为本的,易于使用; (5)它是应用程序和设备独立。我们展示了使用Hermes编写高级策略的示例,并显示如何将此类策略实例化到域和设备,用户和角色,应用程序和操作特定安全配置中的示例。我们还描述了Hifipol内的Hermes集成:浏览器策略管理系统。我们相信Hermes是朝着保护网络生态系统的客户端的必要步骤,并防止或减轻基于Web浏览器的攻击,例如网络钓鱼的当前进入。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号