Semi-Automatic Synthesis Of Security Policies By Invariant-Guided Abduction

FAST'10: Proceedings of the 7th International conference on Formal aspects of security and trust(2011)

引用 2|浏览9
暂无评分
摘要
We present a. specification approach of secured systems as transition systems and security policies as constraints that guard the transitions. In this context, security properties are expressed as invariants. Then we propose an abduction algorithm to generate possible security policies for a given transition-based system. Because abduction is guided by invariants, the generated security policies enforce security properties specified by these invariants. In this framework we are able to tune abduction in two ways in order to: (i) filter out bad security policies and (ii) generate additional possible security policies. Invariant-guided abduction helps designing policies and thus allows using formal methods much earlier in the process of building secured systems. This approach is illustrated on role-based access control systems.
更多
查看译文
关键词
security policy,security property,secured system,additional possible security policy,bad security policy,possible security policy,Invariant-guided abduction,abduction algorithm,specification approach,formal method,Semi-automatic synthesis,invariant-guided abduction
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要