【24h】

Applied dynamic policy selection

机译:应用动态策略选择

获取原文

摘要

Cloud key services are prominent targets for attacks. In fact, every service guarding sensitive data uses a policy system to do so. As of today, such policies are mostly static. However, as system environments change and attacks grow more sophisticated, such static policies cannot always sufficiently cope with attacks and may even unnecessarily hinder the legitimate user. We believe that more fine-grained and reactive protection systems are needed to meet modern security requirements. We propose a concept to separate the concerns of policy enforcement and the policies themselves as a basis for more flexible and dynamic policy enforcement. With policies no longer interfering with a system's business logic, we can introduce strategies and actions which preselect rules based on system information for the policy enforcement to use. In order to understand the characteristics and capabilities of the proposed concept, we implemented two case studies based on CrySIL and XACML. We show that our concept can can be gradually integrated with existing systems while at the same time easing maintenance of policy sets. Furthermore, it enables policy sharing and joint definition and refinement of strategies, actions, and security rules, resulting in powerful security policies at minimal cost. All in all, our solution fosters deployment of reactive security systems.
机译:云关键服务是攻击的突出目标。实际上,每个服务守卫敏感数据都使用策略系统来执行此操作。截至今天,此类政策大多是静态的。但是,随着系统环境的变化和攻击更复杂,这种静态策略不能总是足够应对攻击,甚至可能不必要地阻碍了合法的用户。我们认为,需要更精细和无功的保护系统来满足现代安全要求。我们提出了一个概念,将政策执法和政策本身的关切分开是更灵活和动态的策略执行的基础。通过政策不再干扰系统的业务逻辑,我们可以引入基于系统信息来预订规则的策略和行动,以便使用策略实施。为了了解所提出的概念的特征和能力,我们实施了基于Crysil和Xacmm的两种案例研究。我们表明我们的概念可以逐渐与现有系统集成,同时缓解策略集的维护。此外,它能够实现策略共享和联合定义和改进战略,行动和安全规则,从而最低成本下产生强大的安全策略。总而言之,我们的解决方案促进了无功安全系统的部署。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号