• DocumentCode
    2107440
  • Title

    ReAlSec: A Relational Language for Advanced Security Engineering

  • Author

    Hamdi, M. ; Essaddi, N. ; Boudriga, N.

  • Author_Institution
    Commun. Networks & Security Res. Lab.
  • fYear
    2009
  • fDate
    26-29 May 2009
  • Firstpage
    596
  • Lastpage
    601
  • Abstract
    With the increasing sophistication of attack techniques and scenarios, appropriate automated decision-making systems should be developed. This paper defines a new security language allowing to cope with attack scenarios through the representation of both attacks and security solutions in a single syntactic framework. A subsequent semantic analysis has also been introduced. To implement this reasoning, we introduce a security compiler-like architecture that comes up with substantial novelties with regard to traditional compilers (used in software engineering). The most important innovations are the computation of abstract attack/counter measure specifications and the resolution of the fundamental security equation (FSE). Unlike existing compilation schemes, our approach aims at building a relational specification of the attack through a traversal of its semantic tree. The security solution(s) corresponding the attack of interest is (are) then found by solving the FSE, in the relational algebra of attacks and decisions. Concrete examples have been analyzed in order to highlight the potential of the proposed relational algebra-based security language, called ReAlSec.
  • Keywords
    decision making; program compilers; relational algebra; security of data; software architecture; advanced security engineering; automated decision-making systems; fundamental security equation; relational algebra-based security language; relational language; security compiler-like architecture; software engineering; subsequent semantic analysis; Algebra; Buildings; Computer architecture; Concrete; Counting circuits; Decision making; Equations; Security; Software engineering; Technological innovation;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Advanced Information Networking and Applications, 2009. AINA '09. International Conference on
  • Conference_Location
    Bradford
  • ISSN
    1550-445X
  • Print_ISBN
    978-1-4244-4000-9
  • Electronic_ISBN
    1550-445X
  • Type

    conf

  • DOI
    10.1109/AINA.2009.139
  • Filename
    5076253