• DocumentCode
    2525205
  • Title

    A Formal Model of Policy Reconciliation

  • Author

    Basile, Cataldo ; Lioy, Antonio ; Pitscheider, Christian ; Shilong Zhao

  • Author_Institution
    Dipt. di Autom. e Inf., Politec. di Torino, Turin, Italy
  • fYear
    2015
  • fDate
    4-6 March 2015
  • Firstpage
    587
  • Lastpage
    594
  • Abstract
    This paper proposes a novel approach to perform the reconciliation of security policies by means of user-defined reconciliation strategies. The proposed policy reconciliation model allows several degree of freedom when specifying reconciliation strategies, which can be based not only on rule actions, like most of the works in literature, but also on other rule data (e.g., the conditions) and other external data (e.g., rule priorities, policy priorities). Additionally, it can be applied to reconcile policies at runtime and off-line, that is, it allows the generation of a reconciled policy. Moreover, the reconciliation process generates a detailed report on all the decision taken. Given its expressiveness, the approach can be also applied to simplify the policy specification process. The model has been validated against a practical example, the definition of the application layer filtering policy in a corporate scenario, and its performance has been tested with synthetic policies. Both validation and performance analysis gave encouraging results.
  • Keywords
    government policies; security of data; application layer filtering policy; corporate scenario; degree of freedom; external data; formal model; performance analysis; policy priorities; policy reconciliation model; policy specification process; rule data; rule priorities; security policies; synthetic policies; user-defined reconciliation strategies; Companies; Complexity theory; Correlation; IP networks; Indexes; Magnetic resonance; Security; policy analysis; policy reconciliation; policy specification; security policy;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Parallel, Distributed and Network-Based Processing (PDP), 2015 23rd Euromicro International Conference on
  • Conference_Location
    Turku
  • ISSN
    1066-6192
  • Type

    conf

  • DOI
    10.1109/PDP.2015.42
  • Filename
    7092779