首页> 外文会议>Detection of intrusions and malware, and vulnerability assessment >A Service Dependency Modeling Framework for Policy-Based Response Enforcement
【24h】

A Service Dependency Modeling Framework for Policy-Based Response Enforcement

机译:基于策略的响应执行的服务依赖关系建模框架

获取原文
获取原文并翻译 | 示例

摘要

The use of dynamic access control policies for threat response adapts local response decisions to high level system constraints. However, security policies are often carefully tightened during system design-time, and the large number of service dependencies in a system architecture makes their dynamic adaptation difficult. The enforcement of a single response rule requires performing multiple configuration changes on multiple services. This paper formally describes a Service Dependency Framework (SDF) in order to assist the response process in selecting the policy enforcement points (PEPs) capable of applying a dynamic response rule. It automatically derives elementary access rules from the generic access control, either allowed or denied by the dynamic response policy, so they can be locally managed by local PEPs. SDF introduces a requires/provides model of service dependencies. It models the service architecture in a modular way, and thus provides both extensibility and reusability of model components. SDF is defined using the Architecture Analysis and Design Language, which provides formal concepts for modeling system architectures. This paper presents a systematic treatment of the dependency model which aims to apply policy rules while minimizing configuration changes and reducing resource consumption.
机译:使用动态访问控制策略进行威胁响应可使本地响应决策适应高层系统约束。但是,安全策略通常在系统设计时会被严格收紧,并且系统体系结构中的大量服务依赖项使其难以动态适应。单个响应规则的实施要求对多个服务执行多个配置更改。本文正式描述了服务依赖性框架(SDF),以帮助响应过程选择能够应用动态响应规则的策略执行点(PEP)。它从动态访问策略允许或拒绝的通用访问控制中自动获取基本访问规则,因此可以由本地PEP对其进行本地管理。 SDF引入了服务依赖项的需求/提供模型。它以模块化的方式对服务体系结构进行建模,从而提供了模型组件的可扩展性和可重用性。 SDF是使用架构分析和设计语言定义的,该语言提供了用于建模系统架构的正式概念。本文介绍了对依赖模型的系统处理,该模型旨在应用策略规则,同时最小化配置更改并减少资源消耗。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号