RELIABLE PROCESS FOR SECURITY POLICY DEPLOYMENT
Author(s) -
Stere Preda,
Nora Cuppens-Boulahia,
Frédéric Cuppens,
Joaquín García-Alfaro,
Laurent Toutain
Publication year - 2007
Language(s) - English
Resource type - Conference proceedings
DOI - 10.5220/0002119200050015
Subject(s) - software deployment , computer science , security policy , computer security model , private network , computer security , process (computing) , focus (optics) , network security policy , network security , intrusion detection system , system administrator , set (abstract data type) , access control , security service , information security , operating system , physics , optics , programming language
We focus in this paper on the problem of configuring and managing network security devices, such as Firewalls, Virtual Private Network (VPN) tunnels, and Intrusion Detection Systems (IDSs). Our proposal is the following. First, we formally specify the security requirements of a given system by using an expressive access control model. As a result, we obtain an abstract security policy, which is free of ambiguities, redundancies or unnecessary details. Second, we deploy such an abstract policy through a set of automatic compilations into the security devices of the system. This proposed deployment process not only simplifies the security administrator's job, but also guarantees a resulting configuration free of anomalies and/or inconsistencies.
Accelerating Research
Robert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom
Address
John Eccles HouseRobert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom