论文部分内容阅读
安全策略是系统安全管理的基础,由于系统环境的复杂性在策略配置中不可避免产生冲突,如何有效的检测与消解策略冲突是应用安全策略的关键。文章分析现有安全策略冲突检测方法的不足,提出了一种一般性的策略描述方法,根据造成冲突的不同原因将冲突进行分类并给出冲突的形式化描述。针对不同类型的冲突,从静态和动态的角度出发,提出相应的冲突检测与消解算法,实现自动对安全策略进行冲突检测与消解,为安全策略的进一步实用提供了必要的保障。
Security policy is the foundation of system security management. Because of the complexity of system environment, conflict will inevitably occur in policy configuration. How to effectively detect and resolve policy conflicts is the key to application security policy. This paper analyzes the deficiencies of the existing security policy conflict detection methods and proposes a general strategy description method. According to the different causes of the conflicts, the conflicts are classified and the formal description of the conflicts is given. According to the different types of conflicts, the corresponding conflict detection and resolution algorithms are put forward from the perspective of static and dynamic, so as to automatically detect and resolve the conflict of security policies, which provides the necessary guarantee for the further practical application of security policies.