Bera, P. ; Maity, Soumya ; Ghosh, S.K. ; Dasgupta, Pallab (2010) A query based formal security analysis framework for enterprise LAN In: 2010 10th IEEE International Conference on Computer and Information Technology, 29 June 2010-1 July 2010, Bradford, West Yorkshire, UK.
Full text not available from this repository.
Official URL: http://ieeexplore.ieee.org/document/5578175/
Related URL: http://dx.doi.org/10.1109/CIT.2010.96
Abstract
The complex security constraints in present day enterprise networks (wired or wireless LAN) demand formal analysis of security policy configurations deployed in the network. One of the needs of a network administrator is to evaluate network service accesses through appropriate queries. The security policy is represented as set of rules for allowing/denying various service accesses through the network and may have spatio-temporal access constraints. The role-based access control (RBAC) mechanisms can also be deployed to strengthen the security perimeter. This paper presents a query based security analysis framework for enterprise networks. It evaluates various service access queries which returns the set of services allowed between specified source and destination network zones under spatio-temporal RBAC constraints. The framework includes (i) a distributed network security policy management system; (ii) a formal model for representing the network topology and STRBAC policy configurations; (iii) a query processing module for analyzing the access model with various queries. The queries are evaluated through a SAT based decision procedure. The framework is applicable for both wired and wireless networks.
Item Type: | Conference or Workshop Item (Paper) |
---|---|
Source: | Copyright of this article belongs to Institute of Electrical and Electronics Engineers. |
Keywords: | Formal Method; Network Security; Wireless LAN; Access Control |
ID Code: | 101656 |
Deposited On: | 12 Dec 2016 10:16 |
Last Modified: | 12 Dec 2016 10:16 |
Repository Staff Only: item control page