A query based formal security analysis framework for enterprise LAN

Bera, P. ; Maity, Soumya ; Ghosh, S.K. ; Dasgupta, Pallab (2010) A query based formal security analysis framework for enterprise LAN In: 2010 10th IEEE International Conference on Computer and Information Technology, 29 June 2010-1 July 2010, Bradford, West Yorkshire, UK.

Full text not available from this repository.

Official URL: http://ieeexplore.ieee.org/document/5578175/

Related URL: http://dx.doi.org/10.1109/CIT.2010.96

Abstract

The complex security constraints in present day enterprise networks (wired or wireless LAN) demand formal analysis of security policy configurations deployed in the network. One of the needs of a network administrator is to evaluate network service accesses through appropriate queries. The security policy is represented as set of rules for allowing/denying various service accesses through the network and may have spatio-temporal access constraints. The role-based access control (RBAC) mechanisms can also be deployed to strengthen the security perimeter. This paper presents a query based security analysis framework for enterprise networks. It evaluates various service access queries which returns the set of services allowed between specified source and destination network zones under spatio-temporal RBAC constraints. The framework includes (i) a distributed network security policy management system; (ii) a formal model for representing the network topology and STRBAC policy configurations; (iii) a query processing module for analyzing the access model with various queries. The queries are evaluated through a SAT based decision procedure. The framework is applicable for both wired and wireless networks.

Item Type:Conference or Workshop Item (Paper)
Source:Copyright of this article belongs to Institute of Electrical and Electronics Engineers.
Keywords:Formal Method; Network Security; Wireless LAN; Access Control
ID Code:101656
Deposited On:12 Dec 2016 10:16
Last Modified:12 Dec 2016 10:16

Repository Staff Only: item control page