• DocumentCode
    1199563
  • Title

    A new standard security policy language

  • Author

    Al-Morsy, Mohamed ; Faheem, Hossam M.

  • Author_Institution
    Fac. of Comput. & Inf. Sci., Ain Shams Univ., Cairo
  • Volume
    28
  • Issue
    2
  • fYear
    2009
  • Firstpage
    19
  • Lastpage
    26
  • Abstract
    The article presents a standard security policy language (SSPL) that provides a flexible, formal, dynamic, and unambiguous language to allow the security officers developing their own security policies with the rules in a readable and formal format. The proposed SSPL simplifies the task of developing standard unambiguous policy statement. The policies can be developed in any specific domain free of any restriction (if the ontology exists the policy will be enforceable, or else it will not). The idioms of the domain ontology can be developed and added to the language at runtime. And the SSPL framework will refresh the new concepts. The proposed SSPL allows for policy automation since the framework will receive the policy configuration and send it to the best matched (after comparing the policy rules class with the registered applications classes) security solution.
  • Keywords
    formal languages; security of data; SSPL; access control; domain ontology; formal format; natural language; organizational security policy language management; policy automation; standard security policy language;
  • fLanguage
    English
  • Journal_Title
    Potentials, IEEE
  • Publisher
    ieee
  • ISSN
    0278-6648
  • Type

    jour

  • DOI
    10.1109/MPOT.2008.931574
  • Filename
    4803810