Toward a Formal Characterization of Policy Specification and Analysis


Authors

Arosha Bandara, Seraphin Calo, Jorge Lobo Emil Lupu, Alessandra Russo, Morris Sloman

Abstract

Policy-based management of the security of a military communications network can simplify the configuration process, while increasing security and availability. An effective policy-based approach requires analysis of policies for inconsistencies, and for desired security properties. It also must provide for the refinement of high-level security goals into concrete policies. This paper defines a language based on first-order logic formulae containing explicit time arguments which is expressive enough for specifying a range of authorization and obligation security policies, while supporting the formalisms and automated tools needed for analysis and refinement. Both system behavior and the semantics of the policies themselves are defined in terms of execution traces, to enable reasoning about algorithmic solutions to policy analysis. The paper also proposes some analysis tools based on the use of logical abduction.



Publication Date

September, 2007

Venue

Annual Conference of ITA, 2007

Published To

None

Paper Signficance

This paper has been highlighted as an excellent example of a US/UK collaborative paper
This is a highlighted paper of scientific significance

Publication Type

ITA Conference paper

ITA Area

Project 4, Technical area 2

Download a copy of the paper here

ITAConfPaper-LoboRussoBandaraEtAl-PolicyAnalysis-Final.pdf

Return to main page