Towards alignment of architectural domains in security policy specifications
Franqueira, Virginia N.L. and van Eck, Pascal (2006) Towards alignment of architectural domains in security policy specifications. Technical Report. Centre for Telematics and Information Technology, University of Twente, Enschede.
|
PDF
- Published Version
530Kb |
Abstract
Large organizations need to align the security architecture across three different domains: access control, network layout and physical infrastructure. Security policy specification formalisms are usually dedicated to only one or two of these domains. Consequently, more than one policy has to be maintained, leading to alignment problems. Approaches from the area of model-driven security enable creating graphical models that span all three domains, but these models do not scale well in real-world scenarios with hundreds of applications and thousands of user roles. In this paper, we demonstrate the feasibility of aligning all three domains in a single enforceable security policy expressed in a Prolog-based formalism by using the Law Governed Interaction (LGI) framework. Our approach alleviates the limitations of policy formalisms that are domain-specific while helping to reach scalability by automatic enforcement provided by LGI.
| Item Type: | Monograph (Technical Report) |
|---|---|
| Uncontrolled Keywords (separate with ;): | Architectural domains; Alignment; Policy specification; Security; Law Governed Interaction (LGI) |
| Subjects: | Q Science > Q Science (General) Q Science > QA Mathematics > QA75 Electronic computers. Computer science |
| Schools: | School of Computing Engineering & Physcial Sciences |
| ID Code: | 6096 |
| Deposited By: | Carmit Erez |
| Deposited On: | 01 Nov 2012 16:36 |
| Last Modified: | 01 Nov 2012 16:36 |
Repository Staff Only: item control page
Tools
Tools




