DocumentCode
1199563
Title
A new standard security policy language
Author
Al-Morsy, Mohamed ; Faheem, Hossam M.
Author_Institution
Fac. of Comput. & Inf. Sci., Ain Shams Univ., Cairo
Volume
28
Issue
2
fYear
2009
Firstpage
19
Lastpage
26
Abstract
The article presents a standard security policy language (SSPL) that provides a flexible, formal, dynamic, and unambiguous language to allow the security officers developing their own security policies with the rules in a readable and formal format. The proposed SSPL simplifies the task of developing standard unambiguous policy statement. The policies can be developed in any specific domain free of any restriction (if the ontology exists the policy will be enforceable, or else it will not). The idioms of the domain ontology can be developed and added to the language at runtime. And the SSPL framework will refresh the new concepts. The proposed SSPL allows for policy automation since the framework will receive the policy configuration and send it to the best matched (after comparing the policy rules class with the registered applications classes) security solution.
Keywords
formal languages; security of data; SSPL; access control; domain ontology; formal format; natural language; organizational security policy language management; policy automation; standard security policy language;
fLanguage
English
Journal_Title
Potentials, IEEE
Publisher
ieee
ISSN
0278-6648
Type
jour
DOI
10.1109/MPOT.2008.931574
Filename
4803810
Link To Document