From qualitative to quantitative enforcement of security policy

  • Authors:
  • Fabio Martinelli;Ilaria Matteucci;Charles Morisset

  • Affiliations:
  • IIT-CNR, Security Group, Pisa, Italy;IIT-CNR, Security Group, Pisa, Italy;IIT-CNR, Security Group, Pisa, Italy

  • Venue:
  • MMM-ACNS'12 Proceedings of the 6th international conference on Mathematical Methods, Models and Architectures for Computer Network Security: computer network security
  • Year:
  • 2012

Quantified Score

Hi-index 0.00

Visualization

Abstract

The problem of enforcing a security policy has been particularly well studied over the last decade, following Schneider's seminal work on security automata. We first present in this paper this problem through its qualitative aspect, where one tries to specify and to define a "good" runtime monitor. In particular, we recall that under some conditions, a monitor can be automatically synthesized, using partial model checking. We then introduce some of the quantitative challenges of runtime enforcement, which focus on the problem of defining what does it mean for a monitor to be better than another one, and we sketch several directions that could be explored to tackle this issue.