A Service Dependency Modeling Framework for Policy-Based Response Enforcement

被引:0
|
作者
Kheir, Nizar [1 ,2 ]
Debar, Herve [1 ]
Cuppens, Frederic [2 ]
Cuppens-Boulahia, Nora [2 ]
Viinikka, Jouni [1 ]
机构
[1] France Telecom, R&D Caen, 42 Rue Coutures BP 6243, F-14066 Caen, France
[2] Telecom Bretagne, Plouzane, France
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The use of dynamic access control policies for threat response adapts local response decisions to high level system constraints. However, security policies are often carefully tightened during system design-time, and the large number of service dependencies in a system architecture makes their dynamic adaptation difficult. The enforcement of a single response rule requires performing multiple configuration changes on multiple services. This paper formally describes a Service Dependency Framework (SDF) in order to assist the response process in selecting the policy enforcement points (PEPs) capable of applying a dynamic response rule. It automatically derives elementary access rules from the generic access control, either allowed or denied by the dynamic response policy, so they can be locally managed by local PEPs. SDF introduces a requires/provides model of service dependencies. It models the service architecture in a modular way, and thus provides both extensibility and reusability of model components. SDF is defined using the Architecture Analysis and Design Language, which provides formal concepts for modeling system architect tires. This paper presents a systematic treatment of the dependency model which aims to apply policy rules while minimizing configuration changes and reducing resource consumption.
引用
收藏
页码:176 / +
页数:4
相关论文
共 50 条
  • [1] A policy-based framework for designing strategies for service negotiation
    Cheng, Yu
    Gu, Hua-Mao
    SNPD 2007: EIGHTH ACIS INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING, ARTIFICIAL INTELLIGENCE, NETWORKING, AND PARALLEL/DISTRIBUTED COMPUTING, VOL 2, PROCEEDINGS, 2007, : 826 - +
  • [2] A Policy-based Framework for QoS Management in Service Oriented Environments
    Badidi, Elarbi
    Serhani, M. Adel
    Esmahi, Larbi
    INNOVATIONS AND ADVANCES IN COMPUTER SCIENCES AND ENGINEERING, 2010, : 467 - +
  • [3] A policy-based framework for RBAC
    Nabhen, R
    Jamhour, E
    Maziero, C
    SELF-MANAGING DISTRIBUTED SYSTEMS, 2003, 2867 : 181 - 193
  • [4] A policy-based approach for QoS specification and enforcement in distributed service-oriented architecture
    Wang, CZ
    Wang, GJ
    Chen, A
    Wang, HQ
    Pierce, Y
    Fung, C
    Uczekaj, S
    2005 IEEE INTERNATIONAL CONFERENCE ON SERVICES COMPUTING, VOL 1, PROCEEDINGS, 2005, : 307 - 310
  • [5] Policy-Based Service-Oriented Management for Centralized Networks: Model, Specification and Enforcement
    Zheng, Weiwei
    Wang, Zhili
    Huang, Haoqiu
    Meng, Luoming
    Qiu, Xuesong
    2016 16TH INTERNATIONAL SYMPOSIUM ON COMMUNICATIONS AND INFORMATION TECHNOLOGIES (ISCIT), 2016, : 196 - 200
  • [6] A framework for policy-based Quality of Service (QoS) in an LMDS wireless network
    Parthasarathy, R
    Bostian, CW
    Dasilva, LA
    Midkiff, SF
    Callahan, TM
    PROCEEDINGS OF THE IASTED INTERNATIONAL CONFERENCE ON WIRELESS AND OPTICAL COMMUNICATIONS, 2002, : 398 - 403
  • [7] A service oriented framework for policy-based management of maritime mobile networks
    Kidston, David
    Labbe, Isabelle
    MILCOM 2006, VOLS 1-7, 2006, : 2103 - +
  • [8] A policy-based evaluation framework for quality and security in service oriented Architectures
    Casola, V.
    Fasolino, A. R.
    Mazzocca, N.
    Tramontana, P.
    2007 IEEE INTERNATIONAL CONFERENCE ON WEB SERVICES, PROCEEDINGS, 2007, : 1181 - +
  • [9] Policy-based autonomic control service
    Badr, N
    Taleb-Bendiab, A
    Reilly, D
    FIFTH IEEE INTERNATIONAL WORKSHOP ON POLICIES FOR DISTRIBUTED SYSTEMS AND NETWORKS, PROCEEDINGS, 2004, : 99 - 102
  • [10] Policy-based service registration and discovery
    Phan, Tan
    Han, Jun
    Schneider, Jean-Guy
    Ebringer, Tim
    Rogers, Tony
    ON THE MOVE TO MEANINGFUL INTERNET SYSTEMS 2007: COOPLS, DOA, ODBASE, GADA, AND IS, PT 1, PROCEEDINGS, 2007, 4803 : 417 - +