A Service Dependency Modeling Framework for Policy-Based Response Enforcement

被引:0
|
作者
Kheir, Nizar [1 ,2 ]
Debar, Herve [1 ]
Cuppens, Frederic [2 ]
Cuppens-Boulahia, Nora [2 ]
Viinikka, Jouni [1 ]
机构
[1] France Telecom, R&D Caen, 42 Rue Coutures BP 6243, F-14066 Caen, France
[2] Telecom Bretagne, Plouzane, France
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The use of dynamic access control policies for threat response adapts local response decisions to high level system constraints. However, security policies are often carefully tightened during system design-time, and the large number of service dependencies in a system architecture makes their dynamic adaptation difficult. The enforcement of a single response rule requires performing multiple configuration changes on multiple services. This paper formally describes a Service Dependency Framework (SDF) in order to assist the response process in selecting the policy enforcement points (PEPs) capable of applying a dynamic response rule. It automatically derives elementary access rules from the generic access control, either allowed or denied by the dynamic response policy, so they can be locally managed by local PEPs. SDF introduces a requires/provides model of service dependencies. It models the service architecture in a modular way, and thus provides both extensibility and reusability of model components. SDF is defined using the Architecture Analysis and Design Language, which provides formal concepts for modeling system architect tires. This paper presents a systematic treatment of the dependency model which aims to apply policy rules while minimizing configuration changes and reducing resource consumption.
引用
收藏
页码:176 / +
页数:4
相关论文
共 50 条
  • [41] Policy-based access control framework for large networks
    Duan, Hai-Xin
    Wu, Jian-Ping
    Li, Xing
    Ruan Jian Xue Bao/Journal of Software, 2001, 12 (12): : 1739 - 1747
  • [42] PBMAN: A policy-based management framework for ambient networks
    Kamienski, Carlos
    Fidalgo, Joseane
    Sadok, Djamel
    Lima, Jennifer
    Pereira, Leonardo
    Ohlman, Borje
    SEVENTH IEEE INTERNATIONAL WORKSHOP ON POLICIES FOR DISTRIBUTED SYSTEMS AND NETWORKS, PROCEEDINGS, 2006, : 76 - +
  • [43] Policy-based De-identification Test Framework
    Gerl, Armin
    Becher, Stefan
    2019 IEEE WORLD CONGRESS ON SERVICES (IEEE SERVICES 2019), 2019, : 356 - 357
  • [44] Policy-based access control framework for large networks
    Duan, HX
    Wu, JP
    Li, X
    IEEE INTERNATIONAL CONFERENCE ON NETWORKS 2000 (ICON 2000), PROCEEDINGS: NETWORKING TRENDS AND CHALLENGES IN THE NEW MILLENNIUM, 2000, : 267 - 272
  • [45] Policy-based access control framework for grid computing
    Wu, Jin
    Leangsuksun, Chokchai Box
    Rampure, Vishal
    Ong, Hong
    SIXTH IEEE INTERNATIONAL SYMPOSIUM ON CLUSTER COMPUTING AND THE GRID: SPANNING THE WORLD AND BEYOND, 2006, : 391 - +
  • [46] An Adaptive Policy-Based Framework for Network Services Management
    Leonidas Lymberopoulos
    Emil Lupu
    Morris Sloman
    Journal of Network and Systems Management, 2003, 11 (3) : 277 - 303
  • [47] A DSL Framework for Policy-based Security of Distributed Systems
    Hamdi, Hedi
    Mosbah, Mohamed
    2009 THIRD IEEE INTERNATIONAL CONFERENCE ON SECURE SOFTWARE INTEGRATION AND RELIABILITY IMPROVEMENT, PROCEEDINGS, 2009, : 150 - 158
  • [48] An Autonomic and Policy-based Authorization Framework for OpenFlow Networks
    Rosendo, Daniel
    Endo, Patricia Takako
    Sadok, Djamel
    Kelner, Judith
    2017 13TH INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE MANAGEMENT (CNSM), 2017,
  • [49] Distributed security agent modeling in the policy-based networking
    Seo, HS
    Cho, TH
    PARALLEL AND DISTRIBUTED COMPUTING: APPLICATIONS AND TECHNOLOGIES, PROCEEDINGS, 2004, 3320 : 782 - 786
  • [50] QoS aware policy-based management architecture for service grids
    Magaña, E
    Serrat, J
    Fourteenth IEEE International Workshops on Enabling Technologies: Infrastructure for Collaborative Enterprises, Proceedings, 2005, : 290 - 291