60 likes | 153 Views
VALIDATION OF INTEGRATED POLICY USING ALLOY. Manachai Toahchoodee Manachai@lamar.colostate.edu. Motivation. Various security policies operating together in the same system Integration of policies might need to achieve the desired security requirements
E N D
VALIDATION OF INTEGRATED POLICY USING ALLOY Manachai Toahchoodee Manachai@lamar.colostate.edu
Motivation • Various security policies operating together in the same system • Integration of policies might need to achieve the desired security requirements • Tool is required to model and validate the integrated policyBackground
Our Approach • Transform integrated policy to the form of algebra [Bonatti, Vimercati, Samarati] • Model the transformed policy using Alloy • Validate policy using Alloy analyzer tool
Benefits • Ensure the validity of integrated policy • Simplify the policy • Automatically validate • Make the policy comply with the requirement
References (1) • François Siewe, Antonio Cau, Hussein Zedan, “A compositional framework for access control policies enforcement” • Piero Bonatti, Sabrina De Capitani di Vimercati, Pierangela Samarati, “An algebra for composing access control policies” • Piero Bonatti, Sabrina De Capitani di Vimercati, Pierangela Samarati, “A modular approach to composing access control policies”
References (2) • Hilary H. Hosmer, “The multipolicy paradigm for trusted systems”