A Service Dependency Modeling Framework for Policy-Based Response Enforcement

被引:0
|
作者
Kheir, Nizar [1 ,2 ]
Debar, Herve [1 ]
Cuppens, Frederic [2 ]
Cuppens-Boulahia, Nora [2 ]
Viinikka, Jouni [1 ]
机构
[1] France Telecom, R&D Caen, 42 Rue Coutures BP 6243, F-14066 Caen, France
[2] Telecom Bretagne, Plouzane, France
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The use of dynamic access control policies for threat response adapts local response decisions to high level system constraints. However, security policies are often carefully tightened during system design-time, and the large number of service dependencies in a system architecture makes their dynamic adaptation difficult. The enforcement of a single response rule requires performing multiple configuration changes on multiple services. This paper formally describes a Service Dependency Framework (SDF) in order to assist the response process in selecting the policy enforcement points (PEPs) capable of applying a dynamic response rule. It automatically derives elementary access rules from the generic access control, either allowed or denied by the dynamic response policy, so they can be locally managed by local PEPs. SDF introduces a requires/provides model of service dependencies. It models the service architecture in a modular way, and thus provides both extensibility and reusability of model components. SDF is defined using the Architecture Analysis and Design Language, which provides formal concepts for modeling system architect tires. This paper presents a systematic treatment of the dependency model which aims to apply policy rules while minimizing configuration changes and reducing resource consumption.
引用
收藏
页码:176 / +
页数:4
相关论文
共 50 条
  • [31] Policy-based QoS enforcement for adaptive Big Data Distribution on the Cloud
    El Kassabi, Hadeel T.
    Taleb, Ikbal
    Serhani, Mohamed Adel
    Dssouli, Rachida
    PROCEEDINGS 2016 IEEE SECOND INTERNATIONAL CONFERENCE ON BIG DATA COMPUTING SERVICE AND APPLICATIONS (BIGDATASERVICE 2016), 2016, : 225 - 233
  • [32] Policy-Based Enforcement of Database Security Configuration through Autonomic Capabilities
    Jabbour, Ghassan 'Gus'
    Menasce, Daniel A.
    FOURTH INTERNATIONAL CONFERENCE ON AUTONOMIC AND AUTONOMOUS SYSTEMS (ICAS 2008), 2008, : 188 - +
  • [33] A policy-based approach for reconfiguration management and enforcement in autonomic communication systems
    Chen, Jie
    Zhao, Zhenzhen
    Qu, Di
    Zhang, Ping
    WIRELESS PERSONAL COMMUNICATIONS, 2008, 45 (02) : 145 - 161
  • [34] Using semantics for policy-based Web service composition
    Chun, SA
    Atluri, V
    Adam, NR
    DISTRIBUTED AND PARALLEL DATABASES, 2005, 18 (01) : 37 - 64
  • [35] A policy-based service-oriented grid architecture
    Qu, XL
    Yang, XJ
    Gui, CM
    Fan, WW
    GRID AND COOPERATIVE COMPUTING, PT 2, 2004, 3033 : 597 - 603
  • [36] Using Semantics for Policy-Based Web Service Composition
    Soon Ae Chun
    Vijayalakshmi Atluri
    Nabil R. Adam
    Distributed and Parallel Databases, 2005, 18 : 37 - 64
  • [37] A policy-based service specification for resource reservation in advance
    Karsten, M
    Beriér, N
    Wolf, L
    Steinmetz, R
    DIGITAL CONVERGENCE FOR CREATIVE DIVERGENCE, VOL 2: TECHNICAL INTERACTIVE SESSIONS, 1999, : 82 - 88
  • [38] Policy-based quality of service mapping in distributed systems
    Rudack, M
    Jobmann, K
    Pajares, A
    Esteve, M
    NOMS 2002: IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM: MANAGEMENT SOLUTIONS FOR THE NEW COMMUNICATIONS WORLD, 2002, : 947 - 949
  • [39] Activity policy-based service discovery for pervasive computing
    Kim, Woohyum
    Kang, Saehoon
    Lee, Younghee
    Lee, Dongman
    Ko, Inyoung
    CURRENT TRENDS IN DATABASE TECHNOLOGY - EDBT 2006, 2006, 4254 : 756 - 768
  • [40] A policy-based framework for interoperable digital content management
    Figueira Filho, Fernando Marques
    de Albuquerque, Joao Porto
    de Geus, Paulo Licio
    Krumm, Heiko
    2007 4TH IEEE CONSUMER COMMUNICATIONS AND NETWORKING CONFERENCE, VOLS 1-3, 2007, : 945 - +