Security Policy Analysis using Deductive Spreadsheets1
نویسندگان
چکیده
As security policies get larger and more complex, analysis tools that help users understand and validate security policies are becoming more important. This paper explores the use of deductive spreadsheets for security policy analysis. Deductive spreadsheets combine the power of deductive rules (for specifying policies and analyses) with the usability of spreadsheets. This approach is introduced with a simple example of analyzing information flow allowed by RBAC policies and then applied in two case studies: analysis of computer system configurations and analysis of Security-Enhanced Linux access control policies.
منابع مشابه
Lopol: A Deductive Database Approach to Policy Analysis and Rewriting
This paper presents a method for deductive databasedriven analysis of Security-Enhanced Linux policies. First, it discusses how directives in an SELinux policy can be normalized and encoded as logical relations. Next, the paper describes how to use these relations in conjunction with inference rules to perform a number of simple analyses. The techniques used to detect security characteristics w...
متن کاملA Logic of Access Control
The e ectiveness of an access control mechanism in implementing a security policy in a centralised operating system is often weakened because of the large number of possible access rights involved, informal speci cation of security policy and a lack of tools for assisting systems administrators. Herein we present a logical foundation for automated tools that assist in determining which access r...
متن کاملMapping global policy discourse on antimicrobial resistance
The rising importance of antimicrobial resistance (AMR) to the global health agenda is associated with a growing number of parties voicing their concern about the issue. With more recommendations and policies appearing, understanding the policy process requires making sense of the views, values, interests and goals of each participant. Policy frame analysis provides a method to understand both ...
متن کاملMeasuring gas demand security using Principal Component Analysis (PCA): A case study
Safeguarding the energy security is an important energy policy goal of every country. Assuring sufficient and reliable resources of energy at affordable prices is the main objective of energy security. Due to such reasons as special geopolitical position, terrorist attacks and other unrest in the Middle East, securing Iran’s energy demand and increasing her natural gas exports have turned into ...
متن کاملInvestigate the Quality of Social Security Organization Policy-Making on Social Security Pensioners Life Style Changes
This article has been done with aims to investigate impact of the quality of social security organization policy-making on pensioners' life style in that organization in the city of Mahabad and based on the criteria of environmental, Economic, Social, Political, Health, Personal security, life expectancy, housing and other services have been research case that are the most important factors tha...
متن کامل