DocumentCode :
1405311
Title :
Network-Level Access Control Policy Analysis and Transformation
Author :
Basile, Cataldo ; Cappadonia, Alberto ; Lioy, Antonio
Author_Institution :
Politecnico di Torino, Dipartimento di Automatica ed Informatica, Torino, Italy
Volume :
20
Issue :
4
fYear :
2012
Firstpage :
985
Lastpage :
998
Abstract :
Network-level access control policies are often specified by various people (network, application, and security administrators), and this may result in conflicts or suboptimal policies. We have defined a new formal model for policy representation that is independent of the actual enforcement elements, along with a procedure that allows the easy identification and removal of inconsistencies and anomalies. Additionally, the policy can be translated to the model used by the target access control element to prepare it for actual deployment. In particular, we show that every policy can be translated into one that uses the “First Matching Rule” resolution strategy. Our policy model and optimization procedure have been implemented in a tool that experimentally demonstrates its applicability to real-life cases.
Keywords :
Access control; IP networks; Magnetic resonance; Optimization; Runtime; Servers; Firewall configuration; policy anomalies; policy conflict; policy transformation; policy translation;
fLanguage :
English
Journal_Title :
Networking, IEEE/ACM Transactions on
Publisher :
ieee
ISSN :
1063-6692
Type :
jour
DOI :
10.1109/TNET.2011.2178431
Filename :
6111329
Link To Document :
بازگشت