A novel logic-based automatic approach to constructing compliant security policies

被引:2
作者
Bao YiBao [1 ,2 ,4 ]
Yin LiHua [1 ]
Fang BinXing [1 ,3 ]
Guo Li [1 ]
机构
[1] Chinese Acad Sci, Inst Comp Technol, Beijing 100190, Peoples R China
[2] Informat Engn Univ, Inst Elect Technol, Zhengzhou 450004, Peoples R China
[3] Beijing Univ Posts & Telecommun, Beijing 100190, Peoples R China
[4] Chinese Acad Sci, Grad Univ, Beijing 100049, Peoples R China
基金
中国国家自然科学基金; 国家高技术研究发展计划(863计划);
关键词
security policy; rewriting; logic program; compliance; VERIFICATION; LANGUAGE; SYSTEMS;
D O I
10.1007/s11432-011-4426-1
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
It is significant to automatically detect and resolve the incompliance in security policy. Most existing works in this field focus on compliance verification, and few of them provide approaches to automatically correct the incompliant security policies. This paper proposes a novel approach to automatically transform a given security policy into a compliant one. Given security policy Pi and delegation policy M declared by logic programs, the approach automatically rewrites Pi into a new one Pi(M) which is compliant with M and is readable by the humans. We prove that the algorithm is sound and complete under noninterference assumption. Formally, we show that the security policy query evaluation algorithm with conflict and unsettlement resolution still works very well on Pi(M). The approach is automatic, so it doesn't require a administrator with excess abilities. In this sense, our proposal can help us to save much manpower resource in security management and improves the security assurance abilities.
引用
收藏
页码:149 / 164
页数:16
相关论文
共 24 条
  • [1] A novel logic-based automatic approach to constructing compliant security policies
    BAO YiBao1
    2Institute of Electronic Technology
    3Beijing University of Posts and Telecommunications
    4Graduate University
    ScienceChina(InformationSciences), 2012, 55 (01) : 149 - 164
  • [2] A novel logic-based automatic approach to constructing compliant security policies
    YiBao Bao
    LiHua Yin
    BinXing Fang
    Li Guo
    Science China Information Sciences, 2012, 55 : 149 - 164
  • [3] A Logic-Based Approach for the Verification of UML Timed Models
    Baresi, Luciano
    Morzenti, Angelo
    Motta, Alfredo
    Pourhashem, Mohammad Mehdi K.
    Rossi, Andmatteo
    ACM TRANSACTIONS ON SOFTWARE ENGINEERING AND METHODOLOGY, 2017, 26 (02)
  • [4] Fuzzy logic-based automatic contrast enhancement of satellite images of ocean
    Nair, Madhu S.
    Lakshmanan, Rekha
    Wilscy, M.
    Tatavarti, Rao
    SIGNAL IMAGE AND VIDEO PROCESSING, 2011, 5 (01) : 69 - 80
  • [5] A Fuzzy Logic-Based Approach for Humanized Driver Modelling
    Feng, Yuxiang
    Iravani, Pejman
    Brace, Chris
    JOURNAL OF ADVANCED TRANSPORTATION, 2021, 2021
  • [6] Fuzzy Logic-Based Novel Hybrid Fuel Framework for Modern Vehicles
    Sarwar, Muhammad Hamza
    Shah, Munam Ali
    Ul Islam, Saif
    Maple, Carsten
    Rodrigues, Joel J. P. C.
    Alaulamie, Abdullah A.
    Mussadiq, Shafaq
    Tariq, Usman
    Asghar, Muhammad Nabeel
    IEEE ACCESS, 2020, 8 : 160596 - 160606
  • [7] Fuzzy logic-based approach for identifying the risk importance of human error
    Li Peng-cheng
    Chen Guo-hua
    Dai Li-cao
    Zhang Li
    SAFETY SCIENCE, 2010, 48 (07) : 902 - 913
  • [8] SCOlog: A logic-based approach to analysing supply chain operation dynamics
    Manataki, Areti
    Chen-Burger, Yun-Heh
    Rovatsos, Michael
    EXPERT SYSTEMS WITH APPLICATIONS, 2014, 41 (01) : 23 - 38
  • [9] ZERO-Conflict: A grouping-based approach for automatic generation of IPSec/VPN security policies
    Chen, Kuong-Ho
    Liu, Yuan-Siao
    Liu, Tzong-Jye
    Dow, Chyi-Ren
    LARGE SCALE MANAGEMENT OF DISTRIBUTED SYSTEMS, PROCEEDINGS, 2006, 4269 : 197 - 208
  • [10] Gene Function Hypotheses for the Campylobacter jejuni Glycome Generated by a Logic-Based Approach
    Sternberg, Michael J. E.
    Tamaddoni-Nezhad, Alireza
    Lesk, Victor I.
    Kay, Emily
    Hitchen, Paul G.
    Cootes, Adrian
    van Alphen, Lieke B.
    Lamoureux, Marc P.
    Jarrelle, Harold C.
    Rawlings, Christopher J.
    Soo, Evelyn C.
    Szymanski, Christine M.
    Dell, Anne
    Wren, Brendan W.
    Muggleton, Stephen H.
    JOURNAL OF MOLECULAR BIOLOGY, 2013, 425 (01) : 186 - 197