DocumentCode
1835533
Title
Goal-Based Policies for Self-Protecting Systems
Author
Schütte, Julian
Author_Institution
Fraunhofer AISEC, Germany
fYear
2012
fDate
26-29 March 2012
Firstpage
360
Lastpage
367
Abstract
With the constantly growing complexity and heterogeneity of distributed system, the ability to control their security mechanisms in a human-understandable way becomes increasingly important. Policies, for specifying the behavior of a system in terms of non-functional requirements, have been in use for several years and the Event-Condition-Action (ECA) pattern has been applied in various systems in order to define appropriate reactions to changing conditions. However, ECA policies do not reflect the desired system state but rather on specific actions the system should perform upon the occurrence of certain events, thereby demanding in-depth knowledge about the inner workings of a system and preventing the development of truly "self-protecting" systems, i.e. systems which are able to automatically adapt themselves so as to achieve certain security goals. In this paper, we present a policy framework that abstracts the ECA model to situation-goal (SG) policies, stating which security requirements should hold in a certain situation and thereby bring policies closer to the actual security model the user has in mind. A prototypical implementation of the framework has been done in form of a module for the Apollon policy system.
Keywords
distributed processing; security of data; Apollon policy system; distributed system; event-condition-action pattern; goal-based policies; policy framework; security goals; security mechanism; security requirements; self-protecting systems; situation-goal policies; Adaptation models; Engines; Middleware; Planning; Security; Semantics; Unified modeling language; goal-based policies; policy-based configuration; self-protection;
fLanguage
English
Publisher
ieee
Conference_Titel
Advanced Information Networking and Applications (AINA), 2012 IEEE 26th International Conference on
Conference_Location
Fukuoka
ISSN
1550-445X
Print_ISBN
978-1-4673-0714-7
Type
conf
DOI
10.1109/AINA.2012.141
Filename
6184893
Link To Document