期刊文献+

计算机网络防御策略描述语言研究 被引量:15

A Computer Network Defense Policy Specification Language
下载PDF
导出
摘要 定义了一种计算机网络防御策略描述语言CNDPSL(computer network defense policy specificationlanguage).该语言面向CNDPM模型,能够统一描述保护、检测和响应策略.在CNDPM模型中,给出了抽象策略细化为具体规则的推导原理,并以形式化的方法分析并验证了策略的完备性、一致性和有效性.CNDPSL是一种声明式语言,抽象了网络防御控制的行为,对网络防御需求具有较好的灵活性、可扩展性和适应性.最后给出了策略引擎的原型及其实现.在GTNetS仿真平台中的实验表明,该语言能够自动地转化为具体的技术规则并实现其表达的防御效能. Policy is an essential part of computer network defense, which has important directive to the deployment, implementation, configuration and effects of defense systems. Presently, models and specifications on access control policy work well. However, they can not be directly applied to the whole defense policy area. In this paper, a new computer network defense policy specification language called CNDPSL is proposed to provide a common method of specifying protection, detection and response policies according to a new defined model called CNDPM, which is put forward by extending Or-BAC (organization based access control model). In CNDPM, automatic assignment mechanism is introduced to improve efficiency, and derivative principles are presented to refine abstract policies to concrete rules. Moreover, completeness, validity and consistency of policy are also formally analyzed and demonstrated. CNDPSL is declarative and able to abstract defense control behaviors of network, which makes this language flexible, extensible and adaptable to network defense requirements. Finally, a policy engine is implemented. Detailed experiments in GTNetS platform indicate that CNDSPL can be refined to concrete technical rules automatically, such as ACL (access control list) in firewall, IDS detection rules, response rules,etc, and obtain defense effects it expresses. The above information proves its effectiveness and efficiency.
出处 《计算机研究与发展》 EI CSCD 北大核心 2009年第1期89-99,共11页 Journal of Computer Research and Development
基金 北京市教育委员会共建项目建设计划基金项目(JD100060630) 国家"八六三"高技术研究发展计划基金项目(2007AA01Z407)~~
关键词 计算机网络防御 策略 CNDPM模型 描述语言 策略引擎 computer network defense (CND) policy CNDPM model specification language policy engine
  • 相关文献

参考文献25

  • 1李肖坚.一种计算机网络自组织的协同对抗模型.计算机研究与发展,2005,42:256-260.
  • 2Sloman M S. Policy driven management for distributed systems [J]. Journal of Network and Systems Management, 1994, 2(4): 333-360
  • 3Stern D F. On the buzzword "security policy"[C] //Proc of 1991 IEEE Symp on Security and Privacy. Los Alamitos: IEEE Computer Society, 1991:219-230
  • 4Breslau L, et al. Advances in network simulation [J]. IEEE Computer, 2000, 33(5): 59-67
  • 5Bill Brown, Andrew Cutts, Dennis McGrath, et al. Simulation of cyber attacks with applications in homeland defense training [C] //SPIE 5071. San Jose: SPIE Press, 2003:63-71
  • 6DeLooze L L, McKean P, Mostow J R, et al. Incorporating simulation into the computer security classroom [EB/OL]. (2001) [2008-01-10]. http://fie. engrng. pitt. edu/fie2004/ papers/1575. pdf
  • 7Liljenstam Michael, Liu Jason, Nicol David, et al. RINSE.. The real-time immersive network simulation Environment for network Security Exercises [C] //Proc of the Workshop on Principles of Advanced and Distributed Simulation. San Diego, CA: Simulation Councils, 2005:119-128
  • 8Li Xiao-Jian, Xia Chun-He, Li Li, et al. A scenario description language of network attack and defense [C] // Proc of the IASTED Asian Conf on Modelling and Simulation. Calgary, Canada: ACTA Press, 2007
  • 9Dulay Damianou N, Lupu E, Sloman M, The ponder policy specification language [G] //LNCS 1995: Proc of the Workshop on Policies for Distributed Systems and Networks Policy. New York: Springer, 2001:18-39
  • 10Ylitalo Katri. Policy core information model [EB]OL]. (2000) [2008-01-10]. http://www. cs. helsinki. fi/u/kraatika/ Courses/QoS00a/ylitalo. pdf

共引文献7

同被引文献61

引证文献15

二级引证文献17

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部