The Experts below are selected from a list of 16272 Experts worldwide ranked by ideXlab platform

Chenghua Tang - One of the best experts on this subject based on the ideXlab platform.

  • implementation and realization of Network Security Policy based on rule engine
    Journal of Networks, 2011
    Co-Authors: Chenghua Tang, Yi Xie
    Abstract:

    In order to solve the implementation and realization efficiency problem of the Network information system Security Policy, an improved object-oriented Rete algorithm and its Network structure model are proposed, and on this basis, the rule engine is introduced, where the implementation and realization steps and efficiency analysis are given. Result shows that the algorithm and Network structure can effectively improve the efficiency of system enforcement and realization. The technology can be adapted to establishing and controlling the Policy service in the extensive Network environment.

  • A Verification Algorithm of Network Security Policy Repository
    2009 International Conference on Information Technology and Computer Science, 2009
    Co-Authors: Chenghua Tang
    Abstract:

    The validity of the Network Security Policy has important impacts on the safety performance of Network information system. For purpose of verifying the Network Security Policy repository effectively, a verification model of Security Policy repository based on EHLPN is proposed. The HLPN is expanded, and based on the establishing of EHLPN model directed graph, the relationship of place and transition about the Policy knowledge expression is analyzed, and the verification algorithm of Security Policy repository is established. Result shows that the model can effectively find the structural errors and provide a new solution and reference for verifying and adjusting the Security Policy repository, so as to better ensure Network system Security.

  • a dynamic and self adaptive Network Security Policy realization mechanism
    Network and Parallel Computing, 2008
    Co-Authors: Chenghua Tang
    Abstract:

    Using high-level Security Policy rules to regulate low-level system, the Security management system with a high level of expansibility and flexibility was made. For purpose of managing Network Security Policy duly and flexibly in the complex Network environment, and resolving its issue efficiency, a dynamic and self-adaptive Security Policy realization mechanism is proposed. The accident monitor and Policy life-cycle are put forward, and the impact of safety equipment or user requests, such as system resources found on the flow control can be calculated automatically. The system can independently carry out a dynamic, flexible and real-time to adjust and control in the Network environment and Security needs change. The distribution model is given to response Policy request rapidly, take the appropriate Policy dissemination methods, and reduce PDP computing tasks, system resource consumption, which introduces the concepts of issue affecting factors, Security domain addresses allocation, etc. Expression and making ways of the structure-dissimilarity Policy faced on attribute characters and operation are analyzed emphatically. The effectiveness of the proposed model and algorithms is proved by experiments.

  • Assessment of Network Security Policy based on Security capability
    2008 11th IEEE Singapore International Conference on Communication Systems, 2008
    Co-Authors: Chenghua Tang
    Abstract:

    The validity of the Security Policy has important impacts on the safety performance of Network information system. For purpose of verifying it effectively, an assessment model of Network Security Policy based on Security capability is proposed. The relationship of defense methods, application targets, and information Security attribute characteristics is analyzed based on the establishing of Security domain and Security Policy, and the Network Security capability of Security Policy is evaluated. Result shows that the model can effectively reflect the protect ability of Security Policy. It provides a new solution and reference for assessing and adjusting the Network Security Policy, so as to better ensure system Security.

  • CSSE (3) - Assessment of Network Security Policy Based on Security Capability
    2008 International Conference on Computer Science and Software Engineering, 2008
    Co-Authors: Chenghua Tang
    Abstract:

    The validity of the Security Policy has important impacts on the safety performance of Network information system. For purpose of verifying it effectively, an assessment model of Network Security Policy based on Security capability is proposed. The relationship of defense methods, application targets, and information Security attribute characteristics is analyzed based on the establishing of Security domain and Security Policy, and the Network Security capability of Security Policy is evaluated. Result shows that the model can effectively reflect the protect ability of Security Policy. It provides a new solution and reference for assessing and adjusting the Network Security Policy, so as to better ensure system Security.

Frédéric Cuppens - One of the best experts on this subject based on the ideXlab platform.

  • Towards filtering and alerting rule rewriting on single-component policies
    2016
    Co-Authors: Joaquin Garcia-alfaro, Frédéric Cuppens, Nora Cuppens-boulahia
    Abstract:

    The use of firewalls and Network intrusion detection systems (NIDSs)is the dominant method to survey and guarantee the Security Policy in current corporate Networks. On the one hand, firewalls are traditional Security components which provide means to filter traffic within corporate Networks, as well as to police the incoming and outcoming interaction with the Internet. On the other hand, NIDSs are complementary Security components used to enhance the visibility level of the Network, pointing to configure both firewalls and NIDSs, it is necessary the use of a set of configuration rules, i.e., a set of filtering or alerting rules. Nevertheless, the existence of anomalies within the set of configuration rules of both firewalls and NIDSs is very likely to degrade the Network Security Policy. The discovering and removal of these anomalies is a serious and complex problem to solve. In this paper, we present a set of mechanisms for such a management.

  • Complete analysis of configuration rules to guarantee reliable Network Security policies
    International Journal of Information Security, 2008
    Co-Authors: J. G. Alfaro, N. Boulahia-cuppens, Frédéric Cuppens
    Abstract:

    The use of different Network Security components, such as firewalls and Network intrusion detection systems (NIDSs), is the dominant method to monitor and guarantee the Security Policy in current corporate Networks. To properly configure these components, it is necessary to use several sets of Security rules. Nevertheless, the existence of anomalies between those rules, particularly in distributed multi-component scenarios, is very likely to degrade the Network Security Policy. The discovery and removal of these anomalies is a serious and complex problem to solve. In this paper, we present a complete set of mechanisms for such a management.

  • SAFECOMP - Towards filtering and alerting rule rewriting on single-component policies
    Lecture Notes in Computer Science, 2006
    Co-Authors: Joaquin Garcia-alfaro, Frédéric Cuppens, Nora Cuppens-boulahia
    Abstract:

    The use of firewalls and Network intrusion detection systems (NIDSs) is the dominant method to survey and guarantee the Security Policy in current corporate Networks. On the one hand, firewalls are traditional Security components which provide means to filter traffic within corporate Networks, as well as to police the incoming and outcoming interaction with the Internet. On the other hand, NIDSs are complementary Security components used to enhance the visibility level of the Network, pointing to malicious or anomalous traffic. To properly configure both firewalls and NIDSs, it is necessary the use of a set of configuration rules, i.e., a set of filtering or alerting rules. Nevertheless, the existence of anomalies within the set of configuration rules of both firewalls and NIDSs is very likely to degrade the Network Security Policy. The discovering and removal of these anomalies is a serious and complex problem to solve. In this paper, we present a set of mechanisms for such a management.

  • ESORICS - Analysis of Policy anomalies on distributed Network Security setups
    Computer Security – ESORICS 2006, 2006
    Co-Authors: J. G. Alfaro, Frédéric Cuppens, Nora Cuppens-boulahia
    Abstract:

    The use of different Network Security components, such as firewalls and Network intrusion detection systems (NIDSs), is the dominant method to survey and guarantee the Security Policy in current corporate Networks. On the one hand, firewalls are traditional Security components which provide means to filter traffic within corporate Networks, as well as to police the incoming and outcoming interaction with the Internet. On the other hand, NIDSs are complementary Security components used to enhance the visibility level of the Network, pointing to malicious or anomalous traffic. To properly configure both firewalls and NIDSs, it is necessary to use several sets of filtering and alerting rules. Nevertheless, the existence of anomalies between those rules, particularly in distributed multi-component scenarios, is very likely to degrade the Network Security Policy. The discovering and removal of these anomalies is a serious and complex problem to solve. In this paper, we present a set of algorithms for such a management.

  • A Formal Approach to Specify and Deploy a Network Security Policy
    Formal Aspects in Security and Trust, 1
    Co-Authors: Frédéric Cuppens, Nora Cuppens-boulahia, Thierry Sans, A. Miege
    Abstract:

    Current firewall configuration languages have no well founded semantics. Each firewall implements its own algorithm that parses specific proprietary languages. The main consequence is that Network access control policies are difficult to manage and most firewalls are actually wrongly configured. In this paper, we present an access control language based on XML syntax whose semantics is interpreted in the access control model Or-BAC (Organization Based Access Control). We show how to use this language to specify high-level Network access control policies and then to automatically derive concrete access control rules to configure specific firewalls through a translation process. Our approach provides clear semantics to Network Security Policy specification, makes management of such Policy easier for the administrator and guarantees portability between firewalls.

Nora Cuppens-boulahia - One of the best experts on this subject based on the ideXlab platform.

  • Towards filtering and alerting rule rewriting on single-component policies
    2016
    Co-Authors: Joaquin Garcia-alfaro, Frédéric Cuppens, Nora Cuppens-boulahia
    Abstract:

    The use of firewalls and Network intrusion detection systems (NIDSs)is the dominant method to survey and guarantee the Security Policy in current corporate Networks. On the one hand, firewalls are traditional Security components which provide means to filter traffic within corporate Networks, as well as to police the incoming and outcoming interaction with the Internet. On the other hand, NIDSs are complementary Security components used to enhance the visibility level of the Network, pointing to configure both firewalls and NIDSs, it is necessary the use of a set of configuration rules, i.e., a set of filtering or alerting rules. Nevertheless, the existence of anomalies within the set of configuration rules of both firewalls and NIDSs is very likely to degrade the Network Security Policy. The discovering and removal of these anomalies is a serious and complex problem to solve. In this paper, we present a set of mechanisms for such a management.

  • SAFECOMP - Towards filtering and alerting rule rewriting on single-component policies
    Lecture Notes in Computer Science, 2006
    Co-Authors: Joaquin Garcia-alfaro, Frédéric Cuppens, Nora Cuppens-boulahia
    Abstract:

    The use of firewalls and Network intrusion detection systems (NIDSs) is the dominant method to survey and guarantee the Security Policy in current corporate Networks. On the one hand, firewalls are traditional Security components which provide means to filter traffic within corporate Networks, as well as to police the incoming and outcoming interaction with the Internet. On the other hand, NIDSs are complementary Security components used to enhance the visibility level of the Network, pointing to malicious or anomalous traffic. To properly configure both firewalls and NIDSs, it is necessary the use of a set of configuration rules, i.e., a set of filtering or alerting rules. Nevertheless, the existence of anomalies within the set of configuration rules of both firewalls and NIDSs is very likely to degrade the Network Security Policy. The discovering and removal of these anomalies is a serious and complex problem to solve. In this paper, we present a set of mechanisms for such a management.

  • ESORICS - Analysis of Policy anomalies on distributed Network Security setups
    Computer Security – ESORICS 2006, 2006
    Co-Authors: J. G. Alfaro, Frédéric Cuppens, Nora Cuppens-boulahia
    Abstract:

    The use of different Network Security components, such as firewalls and Network intrusion detection systems (NIDSs), is the dominant method to survey and guarantee the Security Policy in current corporate Networks. On the one hand, firewalls are traditional Security components which provide means to filter traffic within corporate Networks, as well as to police the incoming and outcoming interaction with the Internet. On the other hand, NIDSs are complementary Security components used to enhance the visibility level of the Network, pointing to malicious or anomalous traffic. To properly configure both firewalls and NIDSs, it is necessary to use several sets of filtering and alerting rules. Nevertheless, the existence of anomalies between those rules, particularly in distributed multi-component scenarios, is very likely to degrade the Network Security Policy. The discovering and removal of these anomalies is a serious and complex problem to solve. In this paper, we present a set of algorithms for such a management.

  • A Formal Approach to Specify and Deploy a Network Security Policy
    Formal Aspects in Security and Trust, 1
    Co-Authors: Frédéric Cuppens, Nora Cuppens-boulahia, Thierry Sans, A. Miege
    Abstract:

    Current firewall configuration languages have no well founded semantics. Each firewall implements its own algorithm that parses specific proprietary languages. The main consequence is that Network access control policies are difficult to manage and most firewalls are actually wrongly configured. In this paper, we present an access control language based on XML syntax whose semantics is interpreted in the access control model Or-BAC (Organization Based Access Control). We show how to use this language to specify high-level Network access control policies and then to automatically derive concrete access control rules to configure specific firewalls through a translation process. Our approach provides clear semantics to Network Security Policy specification, makes management of such Policy easier for the administrator and guarantees portability between firewalls.

Li Jing - One of the best experts on this subject based on the ideXlab platform.

  • Research on Network Security Policy Refinement Consistency of Detection and Conflict Resolution Mechanisms
    Computer Science, 2011
    Co-Authors: Li Jing
    Abstract:

    Through Policy-based Network Security management research,this paper analyzed the existing Network secu-rity Policy conflict detection and resolution method shortcomings.Based on Policy refinement of ideas and Security Policy conflicts classification technology,Policy-based Network management Security-level model was established,with exten-ded XACML language description.According to the relationship between Policy behavior,using knowledge reasoning,dynamic layered Security corresponding level of Policy refinement consistency automatic detection and timely conflict resolution were made,letting it has a good reusability and scalability,and is conducive to the improvement of manage-ment efficiency.Policy-based access control refinement application implementation was verified.Finally,some of the fu-ture research directions were discussed.

Ren Zi-ting - One of the best experts on this subject based on the ideXlab platform.