Title :
A new standard security policy language
Author :
Al-Morsy, Mohamed ; Faheem, Hossam M.
Author_Institution :
Fac. of Comput. & Inf. Sci., Ain Shams Univ., Cairo
Abstract :
The article presents a standard security policy language (SSPL) that provides a flexible, formal, dynamic, and unambiguous language to allow the security officers developing their own security policies with the rules in a readable and formal format. The proposed SSPL simplifies the task of developing standard unambiguous policy statement. The policies can be developed in any specific domain free of any restriction (if the ontology exists the policy will be enforceable, or else it will not). The idioms of the domain ontology can be developed and added to the language at runtime. And the SSPL framework will refresh the new concepts. The proposed SSPL allows for policy automation since the framework will receive the policy configuration and send it to the best matched (after comparing the policy rules class with the registered applications classes) security solution.
Keywords :
formal languages; security of data; SSPL; access control; domain ontology; formal format; natural language; organizational security policy language management; policy automation; standard security policy language;
Journal_Title :
Potentials, IEEE
DOI :
10.1109/MPOT.2008.931574