Methods and limitations of security policy reconciliation

被引:22
作者
McDaniel, P
Prakash, A
机构
来源
2002 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, PROCEEDINGS | 2002年
关键词
D O I
10.1109/SECPRI.2002.1004363
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A security policy is a means by which participant session requirements are specified. However, existing frameworks provide limited facilities for the automated reconciliation of participant policies. This paper considers the limits and methods of reconciliation in a general-purpose policy model. We identify an algorithm for efficient two-policy reconciliation, and show that, in the worst-case, reconciliation of three or more policies is intractable. Further, we suggest efficient heuristics for the detection and resolution of intractable reconciliation. Based upon the policy model, we describe the design and implementation of the Ismene policy language. The expressiveness of Ismene, and indirectly of our model, is demonstrated through the representation and exposition of policies supported by existing policy languages. We conclude with brief notes on the integration and enforcement of Ismene policy within the Antigone communication system.
引用
收藏
页码:73 / 87
页数:15
相关论文
共 33 条
[21]  
Hiltunen M. A., 1998, IEE Proceedings-Software, V145, P180, DOI 10.1049/ip-sen:19982298
[22]  
HOUSLEY R, 1999, 1949 RFC
[23]   A logical language for expressing authorizations [J].
Jajodia, S ;
Samarati, P ;
Subrahmanian, VS .
1997 IEEE SYMPOSIUM ON SECURITY AND PRIVACY - PROCEEDINGS, 1997, :31-42
[24]  
LEIGHTON T, 1994, P CRYPTO 93, P456
[25]  
LIU X, 1999, P 17 ACM SOSP CHARL, V33, P80
[26]  
McDaniel P, 2001, DISCEX'01: DARPA INFORMATION SURVIVABILITY CONFERENCE & EXPOSITION II, VOL II, PROCEEDINGS, P55, DOI 10.1109/DISCEX.2001.932159
[27]  
McDaniel P, 1999, USENIX ASSOCIATION PROCEEDINGS OF THE EIGHTH USENIX SECURITY SYMPOSIUM (SECURITY '99), P99
[28]  
MCDANIEL P, 2001, THESIS U MICHIGAN AN
[29]  
Ryutov T., 2000, P DARPA INF SURV C E, P172
[30]  
Schaefer T. J., 1978, C RECORD 10 ANN ACM, P216, DOI DOI 10.1145/800133.804350