A Service Dependency Modeling Framework for Policy-Based Response Enforcement

被引:0
|
作者
Kheir, Nizar [1 ,2 ]
Debar, Herve [1 ]
Cuppens, Frederic [2 ]
Cuppens-Boulahia, Nora [2 ]
Viinikka, Jouni [1 ]
机构
[1] France Telecom, R&D Caen, 42 Rue Coutures BP 6243, F-14066 Caen, France
[2] Telecom Bretagne, Plouzane, France
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The use of dynamic access control policies for threat response adapts local response decisions to high level system constraints. However, security policies are often carefully tightened during system design-time, and the large number of service dependencies in a system architecture makes their dynamic adaptation difficult. The enforcement of a single response rule requires performing multiple configuration changes on multiple services. This paper formally describes a Service Dependency Framework (SDF) in order to assist the response process in selecting the policy enforcement points (PEPs) capable of applying a dynamic response rule. It automatically derives elementary access rules from the generic access control, either allowed or denied by the dynamic response policy, so they can be locally managed by local PEPs. SDF introduces a requires/provides model of service dependencies. It models the service architecture in a modular way, and thus provides both extensibility and reusability of model components. SDF is defined using the Architecture Analysis and Design Language, which provides formal concepts for modeling system architect tires. This paper presents a systematic treatment of the dependency model which aims to apply policy rules while minimizing configuration changes and reducing resource consumption.
引用
收藏
页码:176 / +
页数:4
相关论文
共 50 条
  • [21] A policy-based adaptation method for service composition
    Zhang, Baopeng
    Shi, Yuanchun
    Chen, Yu
    2006 1ST INTERNATIONAL SYMPOSIUM ON PERVASIVE COMPUTING AND APPLICATIONS, PROCEEDINGS, 2006, : 619 - +
  • [22] Design patterns for policy-based service engagements
    Udupi, Yathiraj B.
    Singh, Munindar P.
    2008 IEEE WORKSHOP ON POLICIES FOR DISTRIBUTED SYSTEMS AND NETWORKS, PROCEEDINGS, 2008, : 97 - 100
  • [23] Policy-based service provisioning for mobile users
    Ganna, M
    Horlait, E
    SERVICE ASSURANCE WITH PARTIAL AND INTERMITTENT RESOURCES, PROCEEDINGS, 2004, 3126 : 55 - 66
  • [24] A Flexible Policy-Based Firewall Management Framework
    Wu Jin-hua
    Chen Xiao-su
    Zhao Yi-zhu
    Ni Jun
    PROCEEDINGS OF THE 2008 INTERNATIONAL CONFERENCE ON CYBERWORLDS, 2008, : 192 - 194
  • [25] PleBeuS: a Policy-based Blockchain Selection Framework
    Scheid, Eder J.
    Lakic, Daniel
    Rodrigues, Bruno B.
    Stiller, Burkhard
    NOMS 2020 - PROCEEDINGS OF THE 2020 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM 2020: MANAGEMENT IN THE AGE OF SOFTWARIZATION AND ARTIFICIAL INTELLIGENCE, 2020,
  • [26] AAA: A survey and a policy-based architecture and framework
    Rensing, C
    Hasan
    Karsten, M
    Stiller, B
    IEEE NETWORK, 2002, 16 (06): : 22 - 27
  • [27] A policy enforcement framework for verification and control of service collaboration
    Tsai, W. T.
    Zhou, Xinyu
    Wei, Xiao
    INFORMATION SYSTEMS AND E-BUSINESS MANAGEMENT, 2008, 6 (01) : 83 - 107
  • [28] A policy enforcement framework for verification and control of service collaboration
    W. T. Tsai
    Xinyu Zhou
    Xiao Wei
    Information Systems and e-Business Management, 2008, 6 : 83 - 107
  • [29] Policy-Based Security Modelling and Enforcement Approach for Emerging Embedded Architectures
    Hagan, Matthew
    Siddiqui, Fahad
    Sezer, Sakir
    2018 31ST IEEE INTERNATIONAL SYSTEM-ON-CHIP CONFERENCE (SOCC), 2018, : 84 - 89
  • [30] A Policy-based Approach for Reconfiguration Management and Enforcement in Autonomic Communication Systems
    Jie Chen
    Zhenzhen Zhao
    Di Qu
    Ping Zhang
    Wireless Personal Communications, 2008, 45 : 145 - 161