A novel logic-based automatic approach to constructing compliant security policies

被引:2
|
作者
Bao YiBao [1 ,2 ,4 ]
Yin LiHua [1 ]
Fang BinXing [1 ,3 ]
Guo Li [1 ]
机构
[1] Chinese Acad Sci, Inst Comp Technol, Beijing 100190, Peoples R China
[2] Informat Engn Univ, Inst Elect Technol, Zhengzhou 450004, Peoples R China
[3] Beijing Univ Posts & Telecommun, Beijing 100190, Peoples R China
[4] Chinese Acad Sci, Grad Univ, Beijing 100049, Peoples R China
基金
中国国家自然科学基金; 国家高技术研究发展计划(863计划);
关键词
security policy; rewriting; logic program; compliance; VERIFICATION; LANGUAGE; SYSTEMS;
D O I
10.1007/s11432-011-4426-1
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
It is significant to automatically detect and resolve the incompliance in security policy. Most existing works in this field focus on compliance verification, and few of them provide approaches to automatically correct the incompliant security policies. This paper proposes a novel approach to automatically transform a given security policy into a compliant one. Given security policy Pi and delegation policy M declared by logic programs, the approach automatically rewrites Pi into a new one Pi(M) which is compliant with M and is readable by the humans. We prove that the algorithm is sound and complete under noninterference assumption. Formally, we show that the security policy query evaluation algorithm with conflict and unsettlement resolution still works very well on Pi(M). The approach is automatic, so it doesn't require a administrator with excess abilities. In this sense, our proposal can help us to save much manpower resource in security management and improves the security assurance abilities.
引用
收藏
页码:149 / 164
页数:16
相关论文
共 50 条
  • [41] A Fuzzy Logic-Based Approach for HVAC Systems Control
    Berouine, A.
    Akssas, E.
    Naitmalek, Y.
    Lachhab, F.
    Bakhouya, M.
    Ouladsine, R.
    Essaaidi, M.
    2019 6TH INTERNATIONAL CONFERENCE ON CONTROL, DECISION AND INFORMATION TECHNOLOGIES (CODIT 2019), 2019, : 1510 - 1515
  • [42] A Logic-Based Approach for the Verification of UML Timed Models
    Baresi, Luciano
    Morzenti, Angelo
    Motta, Alfredo
    Pourhashem, Mohammad Mehdi K.
    Rossi, Andmatteo
    ACM TRANSACTIONS ON SOFTWARE ENGINEERING AND METHODOLOGY, 2017, 26 (02)
  • [43] A logic-based approach to scheduling problems with resource constraints
    Pinto, JM
    Grossmann, IE
    COMPUTERS & CHEMICAL ENGINEERING, 1997, 21 (08) : 801 - 818
  • [44] A Semantic Logic-Based Approach to Determine Textual Similarity
    Blanco, Eduardo
    Moldovan, Dan
    IEEE-ACM TRANSACTIONS ON AUDIO SPEECH AND LANGUAGE PROCESSING, 2015, 23 (04) : 683 - 693
  • [45] Conceptual modelling for configuration: A description logic-based approach
    McGuinness, Deborah L.
    Wright, Jon R.
    Artificial Intelligence for Engineering Design, Analysis and Manufacturing: AIEDAM, 1998, 12 (04): : 333 - 344
  • [46] A fuzzy logic-based approach for groundwater vulnerability assessment
    Vahid Nourani
    Sana Maleki
    Hessam Najafi
    Aida Hosseini Baghanam
    Environmental Science and Pollution Research, 2024, 31 : 18010 - 18029
  • [47] Fuzzy Logic-Based Approach to Electronic Circuit Analysis
    Babanli, K. M.
    Kabaoglu, Rana Ortac
    10TH INTERNATIONAL CONFERENCE ON THEORY AND APPLICATION OF SOFT COMPUTING, COMPUTING WITH WORDS AND PERCEPTIONS - ICSCCW-2019, 2020, 1095 : 382 - 389
  • [48] A logic-based approach to model supervisory control systems
    Dell'Acqua, Pierangelo
    Lombardi, Anna
    Pereira, Luis Moniz
    FOUNDATIONS OF INTELLIGENT SYSTEMS, PROCEEDINGS, 2006, 4203 : 534 - 539
  • [49] iML:: A logic-based framework for constructing graphical user interface on mobile agents
    Fukuta, N
    Mizutani, N
    Ozono, T
    Shintani, T
    WEB KNOWLEDGE MANAGEMENT AND DECISION SUPPORTS, 2003, 2543 : 36 - 50
  • [50] A logic-based approach to cache answerability for XPath queries
    Franceschet, M.
    Zimuel, E.
    DATABASE AND XML TECHNOLOGIES, PROCEEDINGS, 2006, 4156 : 46 - 60