• DocumentCode
    2759445
  • Title

    SCAP based configuration analytics for comprehensive compliance checking

  • Author

    Alsaleh, Mohammed Noraden ; Al-Shaer, Ehab

  • Author_Institution
    Dept. of Software & Inf. Syst., Univ. of North Carolina at Charlotte, Charlotte, NC, USA
  • fYear
    2011
  • fDate
    Oct. 31 2011-Nov. 1 2011
  • Firstpage
    1
  • Lastpage
    8
  • Abstract
    Computing systems today have large number of security configuration settings that are designed to offer flexible and robust services. However, incorrect configuration increases the potential of vulnerability and attacks. Security Content Automation Protocol provides a unified mean to automate the process of checking the desktop system compliance using standard interfaces. However, misconfiguration can be identified only if global checking that includes network and desktop configuration is performed, as many of these configurations are highly interdependent. In this work we present a SCAP-based tool that integrates host and network configuration compliance checking in one model and allows for executing comprehensive analysis queries in order to verify security and risk requirements across the end-to-end network as a single system. Our proposed tool translates XCCDF reports generated from SCAP tools into logical objects that can be further composed to create global logical analysis using more advanced security analytic tools such as ConfigChecker and PROLOG-based tools. This project also shows the value of building on the effort of standard tools to improve the state of the art.
  • Keywords
    computer network security; configuration management; conformance testing; cryptographic protocols; formal verification; query processing; software tools; ConflgChecker tools; PROLOG-based tools; SCAP tools; XCCDF reports; comprehensive analysis query; desktop configuration; desktop system compliance; global checking; global logical analysis; host configuration compliance checking; network configuration compliance checking; security analytic tools; security configuration; security content automation protocol; vulnerability; Analytical models; Benchmark testing; Engines; Indexes; Measurement; Security; Software;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Configuration Analytics and Automation (SAFECONFIG), 2011 4th Symposium on
  • Conference_Location
    Arlington, VA
  • Print_ISBN
    978-1-4673-0401-6
  • Electronic_ISBN
    978-1-4673-0400-9
  • Type

    conf

  • DOI
    10.1109/SafeConfig.2011.6111674
  • Filename
    6111674