...
首页> 外文期刊>IEEE systems journal >Security Policy Alignment: A Formal Approach
【24h】

Security Policy Alignment: A Formal Approach

机译:安全策略调整:一种正式方法

获取原文
获取原文并翻译 | 示例

摘要

Security policy alignment concerns the matching of security policies specified at different levels in socio-technical systems, and delegated to different agents, technical and human. For example, the policy that sales data should not leave an organization is refined into policies on door locks, firewalls and employee behavior, and this refinement should be correct with respect to the original policy. Although alignment of security policies in socio-technical systems has been discussed in the literature, especially in relation to business goals, there has been no formal treatment of this topic so far in terms of consistency and completeness of policies. Wherever formal approaches are used in policy alignment, these are applied to well-defined technical access control scenarios instead. Therefore, we aim at formalizing security policy alignment for complex socio-technical systems in this paper, and our formalization is based on predicates over sequences of actions. We discuss how this formalization provides the foundations for existing and future methods for finding security weaknesses induced by misalignment of policies in socio-technical systems.
机译:安全策略一致性涉及在社会技术系统的不同级别上指定的安全策略的匹配,并委派给不同的技术人员和人员。例如,将销售数据不应离开组织的策略改进为关于门锁,防火墙和员工行为的策略,并且这种改进应相对于原始策略是正确的。尽管文献中已经讨论了社会技术系统中安全策略的对齐方式,尤其是与业务目标相关的内容,但是到目前为止,在策略的一致性和完整性方面还没有对该主题进行正式处理。无论在策略调整中使用正式方法的何处,都将这些方法应用于定义明确的技术访问控制方案。因此,本文旨在针对复杂的社会技术系统,对安全策略进行形式化规范化,并且我们的形式化基于动作序列的谓词。我们讨论这种形式化如何为现有和将来的方法提供基础,以发现由社会技术系统中的策略不匹配引起的安全弱点。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号