...
首页> 外文期刊>Computers & Security >A comprehensive approach to the automatic refinement and verification of access control policies
【24h】

A comprehensive approach to the automatic refinement and verification of access control policies

机译:一种自动完善和验证访问控制策略的综合方法

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Access control is one of the building blocks of network security and is often managed by network administrators through the definition of sets of high-level policies meant to regulate network behavior (policy-based management). In this scenario, policy refinement and verification are important processes that have to be dealt with carefully, possibly relaying on computer-aided automated software tools.This paper presents a comprehensive approach for access control policy refinement, verification and, in case errors are detected in the policy implementation, their fixing. The proposed methodology is based on a twofold model able to describe both policies and system configurations and allows, by suitably processing the model, to either propose a system configuration that correctly enforces the policies, or determine whether a specific implementation matches the policy specification also providing hints on how possible anomalies can be fixed. Results on the average complexity of the solution confirm its feasibility in terms of computation time, even for complex networked systems consisting of several hundred nodes. (C) 2018 Elsevier Ltd. All rights reserved.
机译:访问控制是网络安全的基本组成部分之一,通常由网络管理员通过定义旨在规范网络行为的高级策略集(基于策略的管理)进行管理。在这种情况下,策略细化和验证是必须谨慎处理的重要过程,可能依靠计算机辅助自动化软件工具进行中继。本文提出了一种用于访问控制策略细化,验证的全面方法,以防万一在服务器中检测到错误。政策的实施,制定。所提出的方法论基于能够描述策略和系统配置的双重模型,并且允许通过适当地处理模型来提出可以正确实施策略的系统配置,或者确定特定实现是否与还提供的策略规范相匹配。有关如何解决可能的异常的提示。该解决方案的平均复杂度结果证实了其在计算时间方面的可行性,即使对于由数百个节点组成的复杂网络系统也是如此。 (C)2018 Elsevier Ltd.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号