跳到主要导航 跳到搜索 跳到主要内容

The consistency verification of Computer Network Defense Policy and measures

  • Beihang University

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Computer Network Defense Policy is the rules of computer network and security devices. In order to achieve specific security objectives, the network need to choose the defensive measures under certain conditions. In order to generate the measures implemented by the device, it usually requires manual or automated translation from high-level network defense policy. In the translation process, due to the presence of semantic loss, man-made understanding mistakes, device machinery, etc., the high-level policy requirements cannot be completely satisfied. This will result in hiding network security risks or vulnerabilities. Through analysis of the consistency between high-level policy and low-level measures, and pointing out the lack and redundancy between the policy and measures, it can guide the further translation of policy on the device. This paper presents a novel formal and automated method to verify the consistency. When errors are detected, we will point out the location of the misconfiguration. The same time, based on SMT solving tools, it has been implemented in a prototype of consistency verifier. Experiments demonstrate that this tool is able to check the consistency and have good scalability and efficiency.

源语言英语
主期刊名Proceedings of the 2012 World Congress on Information and Communication Technologies, WICT 2012
1052-1055
页数4
DOI
出版状态已出版 - 2012
活动2012 World Congress on Information and Communication Technologies, WICT 2012 - Trivandrum, 印度
期限: 30 10月 20122 11月 2012

出版系列

姓名Proceedings of the 2012 World Congress on Information and Communication Technologies, WICT 2012

会议

会议2012 World Congress on Information and Communication Technologies, WICT 2012
国家/地区印度
Trivandrum
时期30/10/122/11/12

指纹

探究 'The consistency verification of Computer Network Defense Policy and measures' 的科研主题。它们共同构成独一无二的指纹。

引用此