Enforcing provisioning and authorization policy in the Antigone system

  • Authors:
  • Patrick McDaniel;Atul Prakash

  • Affiliations:
  • SIIS Laboratory, Computer Science and Engineering, Pennsylvania State University, USA E-mail: mcdaniel@cse.psu.edu;Electrical Engineering and Computer Science, University of Michigan, USA E-mail: aprakash@eecs.umich.edu

  • Venue:
  • Journal of Computer Security
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

Prior works in communication security policy have focused on general-purpose policy languages and evaluation algorithms. However, because the supporting frameworks often defer enforcement, the correctness of a realization of these policies in software is limited by the quality of domain-specific implementations. This paper introduces the Antigone communication security policy enforcement framework. The Antigone framework fills the gap between representations and enforcement by implementing and integrating the diverse security services needed by policy. Policy is enforced by the run-time composition, configuration, and regulation of security services. We present the Antigone architecture, and demonstrate non-trivial applications and policies. A profile of policy enforcement performance is developed, and key architectural enhancements identified. We also consider the advantages and disadvantages of alternative software architectures appropriate for policy enforcement.