计算机科学 ›› 2011, Vol. 38 ›› Issue (2): 32-37.

• 计算机网络与信息安全 • 上一篇    下一篇

网络安全策略求精一致性检测和冲突消解机制的研究

倪俊,陈晓苏,刘辉宇,李劲   

  1. (华中科技大学计算机科学与技术学院 武汉430074) (恩施州电力总公司 恩施445000) (湖北民族学院信息工程学院 恩施445000)
  • 出版日期:2018-11-16 发布日期:2018-11-16
  • 基金资助:
    本文受国家863计划项目(2007AA10Z309)资助。

Research on Network Security Policy Refinement Consistency of Detection and Conflict Resolution Mechanisms

NI Jun,CHEN Xiao-su,LIU Hui-yu,LI Jing   

  • Online:2018-11-16 Published:2018-11-16

摘要: 通过对基于策略的网络安全管理的研究,分析了现有网络安全策略冲突检测和消解方法存在的不足。基于策略求精的思想和安全策略冲突分类技术,建立基于策略的网络管理安全级模型,并用扩展的XACML语言加以描述。根据策略行为间的关系,采用知识推理技术,动态分层地对相应安全级策略进行一致性自动检测和实时冲突消解,使其具有良好的可重用性和可扩展性,以利于安全策略管理效率的提高。并通过策略求精访问控制的应用实现进行了验证。最后给出了未来的研究方向。

关键词: 网络安全,策略求精,安全级模型,一致性自动检测,知识推理,冲突消解

Abstract: Through policy-based network security management research, this paper analyzed the existing network security policy conflict detection and resolution method shortcomings. Based on policy refinement of ideas and security policy conflicts classification technology, policy-based network management security-level model was established, with extended XACMI_ language description. According to the relationship between policy behavior, using knowledge reasoning,dynamic layered security corresponding level of policy refinement consistency automatic detection and timely conflict resolution were made, letting it has a good reusability and scalability, and is conducive to the improvement of management efficiency. Policy-based access control refinement application implementation was verified. Finally, some of the fulure research directions were discussed.

Key words: Network security, Policy refinement, Security-level model, Consistency of automatic detection, Knowledge reasoning,Conflict resolution

No related articles found!
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!