Enabling automated threat response through the use of a dynamic security policy - Archive ouverte HAL Accéder directement au contenu
Article Dans Une Revue Journal in Computer Virology (JCV) Année : 2007

Enabling automated threat response through the use of a dynamic security policy

Hervé Debar
Frédéric Cuppens
  • Fonction : Auteur
  • PersonId : 863922
Nora Cuppens-Boulahia
  • Fonction : Auteur
  • PersonId : 863921

Résumé

Information systems security issues are currently being addressed using different techniques, such as authentication, encryption and access control, through the definition of security policies, but also using monitoring techniques, in particular intrusion detection systems. We can observe that security monitoring is currently totally decorrelated from security policies, that is security requirements are not linked with the means used to control their fulfillment. Most of the time, security operators have to analyze monitoring results and manually react to provide countermeasures to threats compromising the security policy. The response process is far from trivial, since it both relies on the relevance of the threat analysis and on the adequacy of the selected countermeasures. In this paper, we present an approach aiming at connecting monitoring techniques with security policy management in order to provide response to threat. We propose an architecture allowing to dynamically and automatically deploy a generic security policy into concrete policy instances taking into account the threat level characterized thanks to intrusion detection systems. Such an approach provides means to bridge the gap between existing detection approaches and new requirements, which clearly deal with the development of intrusion prevention systems, enabling a better protection of the resources and services.
Fichier principal
Vignette du fichier
jcv07.pdf (286.58 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-00439845 , version 1 (08-12-2009)

Identifiants

  • HAL Id : hal-00439845 , version 1

Citer

Hervé Debar, Yohann Thomas, Frédéric Cuppens, Nora Cuppens-Boulahia. Enabling automated threat response through the use of a dynamic security policy. Journal in Computer Virology (JCV), 2007, 3 (3), pp.195-210. ⟨hal-00439845⟩
90 Consultations
371 Téléchargements

Partager

Gmail Facebook X LinkedIn More