• DocumentCode
    1835533
  • Title

    Goal-Based Policies for Self-Protecting Systems

  • Author

    Schütte, Julian

  • Author_Institution
    Fraunhofer AISEC, Germany
  • fYear
    2012
  • fDate
    26-29 March 2012
  • Firstpage
    360
  • Lastpage
    367
  • Abstract
    With the constantly growing complexity and heterogeneity of distributed system, the ability to control their security mechanisms in a human-understandable way becomes increasingly important. Policies, for specifying the behavior of a system in terms of non-functional requirements, have been in use for several years and the Event-Condition-Action (ECA) pattern has been applied in various systems in order to define appropriate reactions to changing conditions. However, ECA policies do not reflect the desired system state but rather on specific actions the system should perform upon the occurrence of certain events, thereby demanding in-depth knowledge about the inner workings of a system and preventing the development of truly "self-protecting" systems, i.e. systems which are able to automatically adapt themselves so as to achieve certain security goals. In this paper, we present a policy framework that abstracts the ECA model to situation-goal (SG) policies, stating which security requirements should hold in a certain situation and thereby bring policies closer to the actual security model the user has in mind. A prototypical implementation of the framework has been done in form of a module for the Apollon policy system.
  • Keywords
    distributed processing; security of data; Apollon policy system; distributed system; event-condition-action pattern; goal-based policies; policy framework; security goals; security mechanism; security requirements; self-protecting systems; situation-goal policies; Adaptation models; Engines; Middleware; Planning; Security; Semantics; Unified modeling language; goal-based policies; policy-based configuration; self-protection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Advanced Information Networking and Applications (AINA), 2012 IEEE 26th International Conference on
  • Conference_Location
    Fukuoka
  • ISSN
    1550-445X
  • Print_ISBN
    978-1-4673-0714-7
  • Type

    conf

  • DOI
    10.1109/AINA.2012.141
  • Filename
    6184893