Skip to main navigation Skip to search Skip to main content

Management of exceptions on access control policies

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

The use of languages based on positive or negative expressiveness is very common for the deployment of security policies (i.e., deployment of permissions and prohibitions on firewalls through singlehanded positive or negative condition attributes). Although these languages may allow us to specify any policy, the single use of positive or negative statements alone leads to complex configurations when excluding some specific cases of general rules that should always apply. In this paper we survey such a management and study existing solutions, such as ordering of rules and segmentation of condition attributes, in order to settle this lack of expressiveness. We then point out to the necessity of full expressiveness for combining both negative and positive conditions on firewall languages in order to improve this management of exceptions on access control policies. This strategy offers us a more efficient deployment of policies, even using fewer rules.

Original languageEnglish
Title of host publicationNew Approaches for Security, Privacy and Trust in Complex Environments
Subtitle of host publicationProceedings of the IFIP TC-11 22nd International Information Security Conference (SEC 2007), 14-16 May 2007, Sandton, S. Africa
EditorsHein Venter, Jan Eloff, Mariki Eloff, Les Labuschagne, Rossouw Solms
Pages97-108
Number of pages12
DOIs
Publication statusPublished - 26 Nov 2007
Externally publishedYes

Publication series

NameIFIP International Federation for Information Processing
Volume232
ISSN (Print)1571-5736

Fingerprint

Dive into the research topics of 'Management of exceptions on access control policies'. Together they form a unique fingerprint.

Cite this