首页> 外文会议>International Workshop on Formal Aspects in Security and Trust >Semi-automatic Synthesis of Security Policies by Invariant-Guided Abduction
【24h】

Semi-automatic Synthesis of Security Policies by Invariant-Guided Abduction

机译:通过不变导游的绑架半自动综合安全政策

获取原文

摘要

We present a specification approach of secured systems as transition systems and security policies as constraints that guard the transitions. In this context, security properties are expressed as invariants. Then we propose an abduction algorithm to generate possible security policies for a given transition-based system. Because abduction is guided by invariants, the generated security policies enforce security properties specified by these invariants. In this framework we are able to tune abduction in two ways in order to: (i) filter out bad security policies and (ii) generate additional possible security policies. Invariant-guided abduction helps designing policies and thus allows using formal methods much earlier in the process of building secured systems. This approach is illustrated on role-based access control systems.
机译:我们介绍了安全系统的规范方法,作为转换系统和安全策略,作为保护转换的约束。在此上下文中,安全性属性表示为不变。然后,我们提出了一种绑架算法来为给定的基于转换的系统生成可能的安全策略。由于绑架由不变性引导,所以生成的安全策略强制执行这些不变性指定的安全性属性。在此框架中,我们能够以两种方式调整绑架,以便:(i)过滤掉不良安全策略和(ii)生成其他可能的安全策略。不变导向的绑架有助于设计策略,从而允许在建造安全系统的过程中使用正式方法。在基于角色的访问控制系统上示出了这种方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号