Collaboration between MAC policies and EDS based on a meta-policy approach

被引:0
|
作者
Blanc, M. [1 ]
Briffaut, J. [2 ,3 ]
Lalande, J. -F. [2 ,3 ]
Toinard, C. [2 ,3 ]
机构
[1] Commiss Energy Atom, BP 12, F-91680 Bruyeres Le Chatel, France
[2] LIFO, F-45067 Orleans, France
[3] ENSI Bourges, F-18000 Bourges, France
关键词
security policy; MAC operating systems; distributed policy; intrusion detection;
D O I
10.1109/CTS.2006.25
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
This paper(1) presents a new infrastructure based on a novel meta-policy approach. This solution allows to deploy a MAC kernel within a distributed system. It is a completely decentralized solution that has strong fault tolerance properties. Despite a local control of the updates, each local policy satisfies global security properties. Our IDS approach add new security properties. It prevents any accidental or malicious update of the local policies. Moreover the collaboration between the meta-policy and our IDS system enables to detect illegal sequences of legal operations.
引用
收藏
页码:48 / +
页数:2
相关论文
共 48 条