【24h】

The Case for Abstracting Security Policies

机译:抽象安全策略的情况

获取原文

摘要

As Internet connectivity grows executing un-trusted code becomes an increasingly serious threat Public Key Infrastructure (PKI) and digital signatures offer some degree of protection, but are only part of a solution. In this paper we propose a mechanism of forcing applications to "declare what they intend to do" by means of an abstract behavioural model. A monitoring process is employed to dynamically ensure that programs do not deviate from their pre-declared intention. We focus particularly on the usability, transparency and maintainability of the system, which we believe to have been lacking in similar efforts. In particular we concentrate on (ⅰ) building powerful and maintainable policy specification languages and; (ⅱ) automatic security auditing of policies.
机译:随着Internet连接执行不可信任的代码,成为一个越来越严重的威胁公钥基础架构(PKI)和数字签名提供了一定程度的保护,但只是解决方案的一部分。在本文中,我们提出了一种迫使申请的机制通过抽象行为模型来“宣布他们打算做什么”。采用监测过程动态确保计划不会偏离其预先宣布的意图。我们专注于系统的可用性,透明度和可维护性,我们相信缺乏类似的努力。特别是我们专注于(Ⅰ)建立强大和可维护的政策规范语言; (Ⅱ)政策自动安全审计。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号