DocumentCode :
1199563
Title :
A new standard security policy language
Author :
Al-Morsy, Mohamed ; Faheem, Hossam M.
Author_Institution :
Fac. of Comput. & Inf. Sci., Ain Shams Univ., Cairo
Volume :
28
Issue :
2
fYear :
2009
Firstpage :
19
Lastpage :
26
Abstract :
The article presents a standard security policy language (SSPL) that provides a flexible, formal, dynamic, and unambiguous language to allow the security officers developing their own security policies with the rules in a readable and formal format. The proposed SSPL simplifies the task of developing standard unambiguous policy statement. The policies can be developed in any specific domain free of any restriction (if the ontology exists the policy will be enforceable, or else it will not). The idioms of the domain ontology can be developed and added to the language at runtime. And the SSPL framework will refresh the new concepts. The proposed SSPL allows for policy automation since the framework will receive the policy configuration and send it to the best matched (after comparing the policy rules class with the registered applications classes) security solution.
Keywords :
formal languages; security of data; SSPL; access control; domain ontology; formal format; natural language; organizational security policy language management; policy automation; standard security policy language;
fLanguage :
English
Journal_Title :
Potentials, IEEE
Publisher :
ieee
ISSN :
0278-6648
Type :
jour
DOI :
10.1109/MPOT.2008.931574
Filename :
4803810
Link To Document :
بازگشت