Mining a high level access control policy in a network with multiple firewalls - Archive ouverte HAL Accéder directement au contenu
Article Dans Une Revue Journal of information security and applications Année : 2015

Mining a high level access control policy in a network with multiple firewalls

Résumé

A policy mining approach that aims to automatically extract a high level of abstraction policy from the rules configured on a firewall has been recently proposed. This technique is likely to considerably facilitate firewall management. However, protecting the information system of a business organization usually requires the enforcement of more than one firewall. In this paper, we augment the policy mining approach by an additional processing for a network access control policy mining. We develop the problem of integration of Net-RBAC policies resulting from policy mining over several firewalls in order to mine a high level network policy. Moreover, we show how to verify security properties related to the deployment consistency over the firewalls. We illustrate the network policy mining approach by a realistic example, and we experimentally evaluate the performance of our merger algorithms.
Fichier non déposé

Dates et versions

hal-01207768 , version 1 (01-10-2015)

Identifiants

  • HAL Id : hal-01207768 , version 1

Citer

Safaa Hachana, Nora Cuppens-Bouhlahia, Frédéric Cuppens. Mining a high level access control policy in a network with multiple firewalls. Journal of information security and applications, 2015, 20, pp.61 - 73. ⟨hal-01207768⟩
131 Consultations
0 Téléchargements

Partager

Gmail Facebook X LinkedIn More