Security policy conceptual modeling and formalization for networked information systems

  • Authors:
  • D. TrčEk

  • Affiliations:
  • Institut Jozef Stefan, Dept. of Digital Communications and Networks E6, Jamova 39, Ljubljana, Slovenia and College of Management, Cankarjeva 5, Koper, Slovenia

  • Venue:
  • Computer Communications
  • Year:
  • 2000

Quantified Score

Hi-index 0.24

Visualization

Abstract

Security in networked information systems is a very complex task that ranges from the level of crypto-primitives over crypto-protocols to the level of organizational matters and legislation. All this is comprised in a so-called security policy, which is often treated as an after-thought. One of the main reasons is the lack of appropriate techniques for conceptual modeling of security policy at early stages of system design. The approach in this paper is based on flow controls as one of the key ingredients for defining a security policy. Consequent security services and security architectures are derived by means of the proposed technique, which also bridges the gap to formal techniques. The result is a formalized output that serves as a basis for further refinement in subsequent stages of the modeling process.