期刊文献+

基于分层模型的网络安全策略逐级求精算法 被引量:8

Hierarchical Algorithm of Policy Refinement for Network Security Based on Layered-policy Model
下载PDF
导出
摘要 基于策略的安全防护技术是当前网络安全研究的重点之一,但其中的抽象策略求精问题一直没有得到很好解决,从而导致基于策略的安全应用需要人工干预配置策略.本文基于安全策略的分层管理模型,提出了一个集目标求精和实体求精为一体的安全策略逐级求精算法.该算法首先通过目标求精将抽象策略转化为系统应执行的安全行为,然后通过实体求精确定安全行为的执行环境,从而将抽象策略转化为系统可理解和可执行的操作规则,解决了策略求精问题. The policy-based security defense technology is the key of current network security research. However, the policy refinement hash' t been implemented to satisfaction for the time being, and the policies of application in network security are still configured manually. Integrated with goal refinement method and entity refinement method, an algorithm of policy refinement is proposed in this paper on the basis of layered-policy model for security policy. Using goal refinement method, this algorithm transforms abstract policies into rules of security actions and then works out the executing conditions of security actions with an entity refinement method. All of these convert abstract policy into system-understandable and system-enforceable rules, and hence the solution of policy refinement implementation.
出处 《小型微型计算机系统》 CSCD 北大核心 2007年第6期998-1002,共5页 Journal of Chinese Computer Systems
基金 国家高技术研究发展计划项目(2003AA712022)资助.
关键词 安全策略 分层管理模型 目标求精 实体求精 security policy hierarchical management model goal refinement entity refinement
  • 相关文献

参考文献7

  • 1IETF Policy Working Group.Policy framework[EB/OL].http://www.ietf.org/html.charters/policy-charter.html,Dec.2002.
  • 2Dulay N,Lupu E,Sloman M,et al.A policy deployment model for the ponder language[C].Integrated Network Management Proceedings,IEEE/IFIP International Symposium on May 2001:529-543.
  • 3Duan H,Wu J P,Li X.Policy based access control framework for large networks[C].IEEE International Conference on Networks,September 2000,267-272.
  • 4Damianou N,Dulay N,Lupu E,et al.Tools for domain-based policy management of distributed systems[C].2002 Network Operations and Management Symposium,on April 2002,203-217.
  • 5Moffett J D,Sloman M S.Policy hierarchies for distributed systems management[J].Selected Areas in Communications,Dec.1993,11(9):1404-1414.
  • 6Arosha K Bandara,Emil C Lupu,Jonathan Moffett,et al.A goal-based approach to policy refinement[C].In:Proc.5th IEEE International Workshop on Policies for Distributed Systems and Networks,Aug 2004,229-239.
  • 7Robert Darimont,Axel van Lamsweerde.Formal refinement patterns for goal-driven requirements elaboration[C].In:Proceedings of the 4th ACM SIGSOFT Symposium on Foundations of Software Engineering Oct.1996,179-190.

同被引文献63

引证文献8

二级引证文献16

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部