A DSL for specifying autonomic security management strategies

  • Authors:
  • Ruan He;Marc Lacoste;Jacques Pulou;Jean Leneutre

  • Affiliations:
  • Orange Labs, France;Orange Labs, France;Orange Labs, France;Telecom ParisTech, France

  • Venue:
  • DPM'10/SETOP'10 Proceedings of the 5th international Workshop on data privacy management, and 3rd international conference on Autonomous spontaneous security
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

Existing self-protection frameworks so far hardly addressed the specification of autonomic security adaptation strategies which guide risk-aware selection or reconfiguration of security mechanisms. Domain-Specific Languages (DSL) present many benefits to achieve this goal in terms of simplicity, automated strategy verification, and run-time integration. This paper presents a DSL to describe security adaptation policies. The DSL is based on the condition-action approach and on a taxonomy of threats and applicable reactions. The DSL also allows to capture trade-offs between security and other concerns such as energy efficiency during the decision making phase. A translation mechanism to refine the DSL into a run-time representation, and integrate adaptation policies within legacy self-protection frameworks is also presented.