首页> 外文期刊>Software >Scalable model-based configuration management of security services in complex enterprise networks
【24h】

Scalable model-based configuration management of security services in complex enterprise networks

机译:复杂企业网络中基于扩展的基于模型的安全服务配置管理

获取原文
获取原文并翻译 | 示例
       

摘要

Security administrators face the challenge of designing, deploying and maintaining a variety of configuration files related to security systems, especially in large-scale networks. These files have heterogeneous syntaxes and follow differing semantic concepts. Nevertheless, they are interdependent due to security services having to cooperate and their configuration to be consistent with each other, so that global security policies are completely and correctly enforced. To tackle this problem, our approach supports a comfortable definition of an abstract high-level security policy and provides an automated derivation of the desired configuration files. It is an extension of policy-based management and policy hierarchies, combining model-based management (MBM) with system modularization. MBM employs an object-oriented model of the managed system to obtain the details needed for automated policy refinement. The modularization into abstract subsystems (ASs) segment the system-and the model-into units which more closely encapsulate related system components and provide focused abstract views. As a result, scalability is achieved and even comprehensive IT systems can be modelled in a unified manner. The associated tool MoBaSeC (Model-Based-Service-Configuration) supports interactive graphical modelling, automated model analysis and policy refinement with the derivation of configuration files. We describe the MBM and AS approaches, outline the tool functions and exemplify their applications and results obtained.
机译:安全管理员面临设计,部署和维护与安全系统相关的各种配置文件的挑战,尤其是在大型网络中。这些文件具有不同的语法,并遵循不同的语义概念。但是,由于安全服务必须合作并且它们的配置要彼此一致,因此它们是相互依赖的,因此可以完全正确地实施全局安全策略。为了解决此问题,我们的方法支持轻松定义抽象的高级安全策略,并提供所需配置文件的自动派生。它是基于策略的管理和策略层次结构的扩展,将基于模型的管理(MBM)与系统模块化相结合。 MBM使用受管系统的面向对象模型来获取自动优化策略所需的详细信息。模块化成抽象子系统(AS)会将系统和模型分割成更紧密地封装相关系统组件并提供集中抽象视图的单元。结果,实现了可伸缩性,甚至可以以统一的方式对全面的IT系统进行建模。关联的工具MoBaSeC(基于模型的服务配置)支持交互式图形建模,自动模型分析以及通过导出配置文件进行策略优化。我们描述了MBM和AS方法,概述了工具功能,并举例说明了它们的应用和获得的结果。

著录项

  • 来源
    《Software》 |2011年第3期|p.307-338|共32页
  • 作者单位

    ICMC, University of Sao Paulo, Sao Paulo, SP, Brazil;

    Department of Computer Science, Technical University of Dortmund, Dortmund, Germany;

    Institute of Computing, University of Campinas, Av. Albert Einstein, 1251, 13083-852 Campinas, SP, Brazil;

    Department of Computer Science, Technical University of Dortmund, Dortmund, Germany;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    network security policy; policy-based management; automated policy refinement;

    机译:网络安全策略;基于政策的管理;自动化政策优化;
  • 入库时间 2022-08-17 13:03:50

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号