Multi-constraint Security Policies for Delegated Firewall Administration

  • Authors:
  • Cássio Ditzel Kropiwiec;Edgard Jamhour;Manoel C. Penna;Guy Pujolle

  • Affiliations:
  • LIP6, UPMC, Paris, France 75016;PPGIA, PUCPR, Curitiba, Brazil 80215-901;PPGIA, PUCPR, Curitiba, Brazil 80215-901;LIP6, UPMC, Paris, France 75016

  • Venue:
  • DSOM '08 Proceedings of the 19th IFIP/IEEE international workshop on Distributed Systems: Operations and Management: Managing Large-Scale Service Deployment
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

This work presents a new policy based security framework that is able handle simultaneously and coherently mandatory, discretionary and security property policies. One important aspect of the proposed framework is that each dimension of the security policies can be managed independently, allowing people playing different roles in an organization to define security policies without violating a global security goal. The framework creates an abstract layer that permits to define security policies independently of how they will be enforced. For example, the mandatory and security property polices could be assigned to the risk management staff while the discretionary policies could be delegated among the several departments in the organization.