• DocumentCode
    2283900
  • Title

    Application domain independent policy conflict analysis using information models

  • Author

    Davy, Steven ; Jennings, Brendan ; Strassner, John

  • Author_Institution
    Telecommun. Software & Syst. Group, Waterford Inst. of Technol., Waterford
  • fYear
    2008
  • fDate
    7-11 April 2008
  • Firstpage
    17
  • Lastpage
    24
  • Abstract
    A key part of the policy authoring process is analysis of the potential for newly created or modified policies to conflict with already deployed policies. We propose an approach for policy conflict analysis in which candidate policies (either newly created or modified) are analyzed on a pair-wise basis with already deployed policies, with potential conflicts between the policies being notified to the policy author. Central to the approach is a two-phase algorithm which, querying an information model, firstly determines the relationships between the pair of policies and, secondly, applies an application-specific conflict pattern to determine if the policies should be flagged as potentially conflicting. The algorithm is generic in the sense that all application specific information is encoded in the information model; as long as a minimal set of assumptions regarding the policy model are adhered to it can be applied in arbitrary application domains. In the paper we present the two phase algorithm and describe an implementation in which it is used to detect potential conflicts for both access control and filtering (firewall) policies.
  • Keywords
    authorisation; computer network management; access control; application domain; application specific information; application-specific conflict pattern; firewall filtering policies; independent policy conflict analysis; information model querying; information models; pair-wise basis; policy authoring process; two-phase algorithm; Access control; Algorithm design and analysis; Application software; Data mining; Filtering algorithms; Information analysis; Information management; Phase detection; Software systems; Unified modeling language; Conflict Detection; Information Model; Policy Based Management;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network Operations and Management Symposium, 2008. NOMS 2008. IEEE
  • Conference_Location
    Salvador, Bahia
  • ISSN
    1542-1201
  • Print_ISBN
    978-1-4244-2065-0
  • Electronic_ISBN
    1542-1201
  • Type

    conf

  • DOI
    10.1109/NOMS.2008.4575112
  • Filename
    4575112