• DocumentCode
    2008746
  • Title

    Using an Information Model and Associated Ontology for Selection of Policies for Conflict Analysis

  • Author

    Davy, Steven ; Jennings, Brendan ; Strassner, John

  • Author_Institution
    Waterford Inst. of Technol., Waterford
  • fYear
    2008
  • fDate
    2-4 June 2008
  • Firstpage
    82
  • Lastpage
    85
  • Abstract
    We present an analysis process targeting identification of potential policy conflicts within sets of policies relating to multiple network devices and the security services deployed on them. The process targets pre-deployment identification of potential conflicts between a newly created (or modified) policy and already deployed policies. It employs an algorithm which, with the aid of an ontology, selects the relevant subset of policies that should be compared with the "candidate" policy, together with an algorithm that identifies the relationships between a given pair of policies and compares these to a conflict signature pattern encoded in an information model. Operation of the process is illustrated via a scenario describing how it can identify conflicts between firewall filtering policies and IPSec VPN policies that are deployed on different network devices.
  • Keywords
    digital signatures; ontologies (artificial intelligence); security of data; IPSec VPN policies; analysis process targeting identification; associated ontology; conflict analysis; conflict signature pattern; firewall filtering policies; information model; multiple network devices; policy selection; potential policy conflicts; pre-deployment identification; security services; Algorithm design and analysis; Communication networks; Conferences; Context-aware services; Filtering; Information analysis; Information security; Ontologies; USA Councils; Virtual private networks; Policy Conflict Analysis; Policy Selection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Policies for Distributed Systems and Networks, 2008. POLICY 2008. IEEE Workshop on
  • Conference_Location
    Palisades, NY
  • Print_ISBN
    978-0-7695-3133-5
  • Type

    conf

  • DOI
    10.1109/POLICY.2008.33
  • Filename
    4556583