A security management information model derivation framework: from goals to configurations

  • Authors:
  • R. Laborde;F. Barrère;A. Benzekri

  • Affiliations:
  • Université Paul Sabatier – IRIT/SIERA, Toulouse;Université Paul Sabatier – IRIT/SIERA, Toulouse;Université Paul Sabatier – IRIT/SIERA, Toulouse

  • Venue:
  • FAST'05 Proceedings of the Third international conference on Formal Aspects in Security and Trust
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

Security mechanisms enforcement consists in configuring devices with the aim that they cooperate and guarantee the defined security goals. In the network context, this task is complex due to the number, the nature, and the interdependencies of the devices to consider. We propose in this article a global and formal framework which models the network security management information from the security goals to the security mechanisms configurations. The process is divided into three steps. First, the security goals are specified and the specification consistency is checked. Secondly, the network security tactics are defined. An evaluation method guarantees the consistency and the correctness against the security goals. Finally, the framework verifies that the network security tactics can be enforced by the real security mechanisms.