首页> 外文会议>2011 IEEE International Symposium on Network Computing and Applications >Validation of Security Solutions for Communication Networks: A Policy-Based Approach
【24h】

Validation of Security Solutions for Communication Networks: A Policy-Based Approach

机译:通讯网络安全解决方案的验证:一种基于策略的方法

获取原文

摘要

Typically, security solutions are defined to meet the requirements of security policies, and are configured to implement some of their rules. Approaches proposed so far in the literature to validate security solutions have merely taken interest to the need of: a) describing the security policy used to define and configure these solutions b) generating executable description of attack scenarios targeting the secured system and c) verifying whether the secured systems react as expected. In this paper we develop a logic-based approach for the modeling of security policies and solutions based on the concept of observations, and the generation of executable scenarios of attacks. This approach provides a unified formalism for the specification of security policies, security solutions, library of legitimate actions and attacks, and correctness rules in the form of predicates over executions. We propose a modeling of two types of security solutions, namely passive and active solutions. We develop a Model Checker to generate executable scenarios of attacks, verify the security state of the system, and test whether the solutions react as expected to security attacks. A case study is proposed to illustrate the proposal.
机译:通常,安全解决方案定义为满足安全策略的要求,并配置为实施其某些规则。迄今为止,文献中提出的用于验证安全解决方案的方法仅引起了以下需求:a)描述用于定义和配置这些解决方案的安全策略b)生成针对受保护系统的攻击方案的可执行描述,以及c)验证是否安全系统会按预期做出反应。在本文中,我们基于观察的概念以及攻击的可执行方案的生成,开发了一种基于逻辑的方法来对安全策略和解决方案进行建模。这种方法以谓词超过执行的形式为安全策略,安全解决方案,合法动作和攻击的库以及正确性规则的规范提供了统一的形式主义。我们建议对两种类型的安全解决方案进行建模,即被动解决方案和主动解决方案。我们开发了一个Model Checker,以生成可执行的攻击方案,验证系统的安全状态,并测试解决方案是否对安全攻击做出了预期的反应。提出了一个案例研究来说明该提议。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号