• DocumentCode
    3055245
  • Title

    A policy deployment model for the Ponder language

  • Author

    Dulay, N. ; Lupu, E. ; Sloman, M. ; Damianou, N.

  • Author_Institution
    Dept. of Comput., Imperial Coll. of Sci., Technol. & Med., London, UK
  • fYear
    2001
  • fDate
    2001
  • Firstpage
    529
  • Lastpage
    543
  • Abstract
    Policies are rules that govern the choices in behaviour of a system. Security policies define what actions are permitted or not permitted, for what or for whom, and under what conditions. Management policies define what actions need to be carried out when specific events occur within a system or what resources must be allocated under specific conditions. There is considerable interest in the use of policies for the security and management of large-scale networks and distributed services. Existing policy work has focussed on specification, information models and application-specific policy enforcement. We address the important goal of providing a general-purpose deployment model for policies that is independent of the underlying policy enforcement mechanisms and can be employed in mixed policy environments. In this paper, we present a deployment model that is object-oriented and addresses the instantiation, distribution and enabling of policies as well as the disabling, unloading and deletion of policies. The model defines objects for policies, for domains, and for the policy enforcement agent and outlines the interactions needed between them. The model also caters for changes in the memberships of domains since such changes also effect policy enforcement. The model forms part of the run-time support for Ponder; a new policy language that combines structuring ideas from object-oriented languages with a common set of policy basic types
  • Keywords
    computer network management; distributed object management; object-oriented languages; specification languages; telecommunication security; Ponder language; deletion; disabling; distributed services; distribution; domains; enabling; general-purpose deployment model; instantiation; large-scale networks; management; mixed policy environments; object-oriented languages; object-oriented system; policy basic types; policy deployment model; policy enforcement agent; run-time support; security; structuring ideas; unloading; Computer network management; Data security; Educational institutions; Information security; Large-scale systems; Object oriented modeling; Quality management; Resource management; Runtime; Specification languages;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Integrated Network Management Proceedings, 2001 IEEE/IFIP International Symposium on
  • Conference_Location
    Seattle, WA
  • Print_ISBN
    0-7803-6719-7
  • Type

    conf

  • DOI
    10.1109/INM.2001.918064
  • Filename
    918064