Résumé
We focus in this paper on the problem of configuring and managing network security devices, such as Firewalls, Virtual Private Network (VPN) tunnels, and Intrusion Detection Systems (IDSs). Our proposal is the following. First, we formally specify the security requirements of a given system by using an expressive access control model. As a result, we obtain an abstract security policy, which is free of ambiguities, redundancies or unnecessary details. Second, we deploy such an abstract policy through a set of automatic compilations into the security devices of the system. This proposed deployment process not only simplifies the security administrator's job, but also guarantees a resulting configuration free of anomalies and/or inconsistencies.
| langue originale | Anglais |
|---|---|
| Pages | 5-15 |
| Nombre de pages | 11 |
| état | Publié - 1 déc. 2007 |
| Modification externe | Oui |
| Evénement | SECRYPT 2007 - International Conference on Security and Cryptography - Barcelona, Espagne Durée: 28 juil. 2007 → 31 juil. 2007 |
Une conférence
| Une conférence | SECRYPT 2007 - International Conference on Security and Cryptography |
|---|---|
| Pays/Territoire | Espagne |
| La ville | Barcelona |
| période | 28/07/07 → 31/07/07 |
Empreinte digitale
Examiner les sujets de recherche de « Reliable process for security policy deployment ». Ensemble, ils forment une empreinte digitale unique.Contient cette citation
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver