DocumentCode
2107440
Title
ReAlSec: A Relational Language for Advanced Security Engineering
Author
Hamdi, M. ; Essaddi, N. ; Boudriga, N.
Author_Institution
Commun. Networks & Security Res. Lab.
fYear
2009
fDate
26-29 May 2009
Firstpage
596
Lastpage
601
Abstract
With the increasing sophistication of attack techniques and scenarios, appropriate automated decision-making systems should be developed. This paper defines a new security language allowing to cope with attack scenarios through the representation of both attacks and security solutions in a single syntactic framework. A subsequent semantic analysis has also been introduced. To implement this reasoning, we introduce a security compiler-like architecture that comes up with substantial novelties with regard to traditional compilers (used in software engineering). The most important innovations are the computation of abstract attack/counter measure specifications and the resolution of the fundamental security equation (FSE). Unlike existing compilation schemes, our approach aims at building a relational specification of the attack through a traversal of its semantic tree. The security solution(s) corresponding the attack of interest is (are) then found by solving the FSE, in the relational algebra of attacks and decisions. Concrete examples have been analyzed in order to highlight the potential of the proposed relational algebra-based security language, called ReAlSec.
Keywords
decision making; program compilers; relational algebra; security of data; software architecture; advanced security engineering; automated decision-making systems; fundamental security equation; relational algebra-based security language; relational language; security compiler-like architecture; software engineering; subsequent semantic analysis; Algebra; Buildings; Computer architecture; Concrete; Counting circuits; Decision making; Equations; Security; Software engineering; Technological innovation;
fLanguage
English
Publisher
ieee
Conference_Titel
Advanced Information Networking and Applications, 2009. AINA '09. International Conference on
Conference_Location
Bradford
ISSN
1550-445X
Print_ISBN
978-1-4244-4000-9
Electronic_ISBN
1550-445X
Type
conf
DOI
10.1109/AINA.2009.139
Filename
5076253
Link To Document