Title :
Developing dynamic security policies
Author :
Naldurg, Prasad ; Campbell, Roy H. ; Mickunas, M. Dennis
Author_Institution :
Dept. of Comput. Sci., Illinois Univ., Champaign, IL, USA
fDate :
6/24/1905 12:00:00 AM
Abstract :
In this paper we define and provide a general construction for a class of policies we call dynamic policies. In most existing systems, policies are implemented and enforced by changing the operational parameters of shared system objects. These policies do not account for the behavior of the entire system, and enforcing these policies can have unexpected interactive or concurrent behavior. We present a policy specification, implementation, and enforcement methodology based on formal models of interactive behavior and satisfiability of system properties. We show that changing the operational parameters of our policy implementation entities does not affect the behavioral guarantees specified by the properties. We demonstrate the construction of dynamic access control policies based on safety property specifications and describe an implementation of these policies in the Seraphim active network architecture. We present examples of reactive security systems that demonstrate the power and dynamism of our policy implementations. We also describe other types of dynamic policies for information flow and availability based on safety, liveness, fairness, and other properties. We believe that dynamic policies are important building blocks of reactive security solutions for active networks.
Keywords :
computer network management; security of data; Seraphim active network; dynamic policies; formal models; interactive behavior; policy development life-cycle; reactive security; satisfiability; Access control; Application software; Computer science; Contracts; Control systems; Information security; Power system management; Power system security; Safety; Software maintenance;
Conference_Titel :
DARPA Active NEtworks Conference and Exposition, 2002. Proceedings
Print_ISBN :
0-7695-1564-9
DOI :
10.1109/DANCE.2002.1003494