Title :
A Formal Model of Policy Reconciliation
Author :
Basile, Cataldo ; Lioy, Antonio ; Pitscheider, Christian ; Shilong Zhao
Author_Institution :
Dipt. di Autom. e Inf., Politec. di Torino, Turin, Italy
Abstract :
This paper proposes a novel approach to perform the reconciliation of security policies by means of user-defined reconciliation strategies. The proposed policy reconciliation model allows several degree of freedom when specifying reconciliation strategies, which can be based not only on rule actions, like most of the works in literature, but also on other rule data (e.g., the conditions) and other external data (e.g., rule priorities, policy priorities). Additionally, it can be applied to reconcile policies at runtime and off-line, that is, it allows the generation of a reconciled policy. Moreover, the reconciliation process generates a detailed report on all the decision taken. Given its expressiveness, the approach can be also applied to simplify the policy specification process. The model has been validated against a practical example, the definition of the application layer filtering policy in a corporate scenario, and its performance has been tested with synthetic policies. Both validation and performance analysis gave encouraging results.
Keywords :
government policies; security of data; application layer filtering policy; corporate scenario; degree of freedom; external data; formal model; performance analysis; policy priorities; policy reconciliation model; policy specification process; rule data; rule priorities; security policies; synthetic policies; user-defined reconciliation strategies; Companies; Complexity theory; Correlation; IP networks; Indexes; Magnetic resonance; Security; policy analysis; policy reconciliation; policy specification; security policy;
Conference_Titel :
Parallel, Distributed and Network-Based Processing (PDP), 2015 23rd Euromicro International Conference on
Conference_Location :
Turku
DOI :
10.1109/PDP.2015.42