The Community for Technology Leaders
2015 23rd Euromicro International Conference on Parallel, Distributed and Network-Based Processing (PDP) (2015)
Turku, Finland
March 4, 2015 to March 6, 2015
ISSN: 1066-6192
ISBN: 978-1-4799-8491-6
pp: 587-594
ABSTRACT
This paper proposes a novel approach to perform the reconciliation of security policies by means of user-defined reconciliation strategies. The proposed policy reconciliation model allows several degree of freedom when specifying reconciliation strategies, which can be based not only on rule actions, like most of the works in literature, but also on other rule data (e.g., the conditions) and other external data (e.g., rule priorities, policy priorities). Additionally, it can be applied to reconcile policies at runtime and off-line, that is, it allows the generation of a reconciled policy. Moreover, the reconciliation process generates a detailed report on all the decision taken. Given its expressiveness, the approach can be also applied to simplify the policy specification process. The model has been validated against a practical example, the definition of the application layer filtering policy in a corporate scenario, and its performance has been tested with synthetic policies. Both validation and performance analysis gave encouraging results.
INDEX TERMS
Security, Magnetic resonance, IP networks, Companies, Indexes, Complexity theory, Correlation
CITATION

C. Basile, A. Lioy, C. Pitscheider and S. Zhao, "A Formal Model of Policy Reconciliation," 2015 23rd Euromicro International Conference on Parallel, Distributed and Network-Based Processing (PDP), Turku, Finland, 2015, pp. 587-594.
doi:10.1109/PDP.2015.42
190 ms
(Ver 3.3 (11022016))