Applied dynamic policy selection
Autor: | Florian Reimair, Bernd Prünster, Andreas Reiter, Christian Ertler |
---|---|
Rok vydání: | 2016 |
Předmět: |
Service (systems architecture)
Authentication business.industry Computer science 010401 analytical chemistry 05 social sciences XACML Cloud computing Access control Security policy Computer security computer.software_genre 01 natural sciences 0104 chemical sciences Business logic Network security policy 0501 psychology and cognitive sciences business computer 050107 human factors computer.programming_language |
Zdroj: | CNS |
DOI: | 10.1109/cns.2016.7860542 |
Popis: | Cloud key services are prominent targets for attacks. In fact, every service guarding sensitive data uses a policy system to do so. As of today, such policies are mostly static. However, as system environments change and attacks grow more sophisticated, such static policies cannot always sufficiently cope with attacks and may even unnecessarily hinder the legitimate user. We believe that more fine-grained and reactive protection systems are needed to meet modern security requirements. We propose a concept to separate the concerns of policy enforcement and the policies themselves as a basis for more flexible and dynamic policy enforcement. With policies no longer interfering with a system's business logic, we can introduce strategies and actions which preselect rules based on system information for the policy enforcement to use. In order to understand the characteristics and capabilities of the proposed concept, we implemented two case studies based on CrySIL and XACML. We show that our concept can can be gradually integrated with existing systems while at the same time easing maintenance of policy sets. Furthermore, it enables policy sharing and joint definition and refinement of strategies, actions, and security rules, resulting in powerful security policies at minimal cost. All in all, our solution fosters deployment of reactive security systems. |
Databáze: | OpenAIRE |
Externí odkaz: |