A specification language for information security policies

  • Authors:
  • Juan Manuel Garcia

  • Affiliations:
  • Division de Estudios de Posgrado, FIE, Universidad Michoacana de San Nicolas de Hidalgo, Morelia, Mexico

  • Venue:
  • CIS'09 Proceedings of the international conference on Computational and information science 2009
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

On an information system, a security policy specifies constraints on resources accessed by processes and information flow among them, and also constraints on external access by outsiders. In order to enforce an information security policy, system administrators face two main problems: First, security policy is often stated informally, leading to ambiguity, inconsistency and incompleteness, and in second place, security policy constraints must be translated on several low level specifications such as operating system access control rules, firewall filtering rules, etc. Is a difficult task to verify if those low level specifications actually enforce the security policy. In this paper we present an information security specification based on process calculus which could be translated to low level specifications.