Skip to main navigation Skip to search Skip to main content

Verification of security policy enforcement in enterprise systems

  • Stony Brook University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Many security requirements for enterprise systems can be expressed in a natural way as high-level access control policies. A high-level policy may refer to abstract information resources, independent of where the information is stored; it controls both direct and indirect accesses to the information; it may refer to the context of a request, i.e., the request's path through the system; and its enforcement point and enforcement mechanism may be unspecified. Enforcement of a high-level policy may depend on the system architecture and the configurations of a variety of security mechanisms, such as firewalls, host login permissions, file permissions, DBMS access control, and application-specific security mechanisms. This paper presents a framework in which all of these can be conveniently and formally expressed, a method to verify that a high-level policy is enforced, and an algorithm to determine a trusted computing base for each resource.

Original languageEnglish
Title of host publicationEmerging Challenges for Security, Privacy and Trust - 24th IFIP TC 11 International Information Security Conference, SEC 2009, Proceedings
Pages202-213
Number of pages12
DOIs
StatePublished - 2009
Event24th IFIP TC11 International Information Security Conference, SEC 2009 - Pafos, Cyprus
Duration: May 18 2009May 20 2009

Publication series

NameIFIP Advances in Information and Communication Technology
Volume297
ISSN (Print)1868-4238

Conference

Conference24th IFIP TC11 International Information Security Conference, SEC 2009
Country/TerritoryCyprus
CityPafos
Period05/18/0905/20/09

Fingerprint

Dive into the research topics of 'Verification of security policy enforcement in enterprise systems'. Together they form a unique fingerprint.

Cite this