首页> 外文期刊>Information Security, IET >Integrated security analysis framework for an enterprise network - a formal approach
【24h】

Integrated security analysis framework for an enterprise network - a formal approach

机译:企业网络的集成安全性分析框架-正式方法

获取原文
获取原文并翻译 | 示例
           

摘要

In a typical enterprise network, correct implementation of security policies is becoming increasingly difficult owing to complex security constraints and dynamic changes in network topology. Usually, the network security policy is defined as the collection of service access rules between various network zones. The specification of the security policy is often incomplete since all possible service access paths may not be explicitly covered. This policy is implemented in the network interfaces in a distributed fashion through sets of access control (ACL) rules. Formally verifying whether the distributed ACL implementation conforms to the security policy is a major requirement. The complexity of the problem is compounded as some combination of network services may lead to inconsistent hidden access paths. Further, failure of network link(s) may result in the formation of alternative routing paths and thus the existing security implementation may defy the policy. In this study, an integrated formal verification and fault analysis framework has been proposed which derives a correct ACL implementation with respect to given policy specification and also ensures that the implementation is fault tolerant to certain number of link failures. The verification incorporates boolean modelling of the security policies and ACL implementations and then formulates a satisfiability checking problem.
机译:在典型的企业网络中,由于复杂的安全约束和网络拓扑结构的动态变化,正确实施安全策略变得越来越困难。通常,网络安全策略定义为各个网络区域之间的服务访问规则的集合。由于未明确涵盖所有可能的服务访问路径,因此安全策略的规范通常不完整。通过访问控制(ACL)规则集以分布式方式在网络接口中实施此策略。正式验证分布式ACL实现是否符合安全策略是主要要求。由于网络服务的某种组合可能导致不一致的隐藏访问路径,因此问题的复杂性更加复杂。此外,网络链路的故障可能导致形成替代路由路径,因此现有的安全实现可能违反该策略。在这项研究中,提出了一个集成的形式验证和故障分析框架,该框架针对给定的策略规范得出了正确的ACL实施方案,并且还确保了该实施方案对一定数量的链路故障具有容错能力。验证结合了安全策略和ACL实现的布尔模型,然后提出了可满足性检查问题。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号