Checking Security Policy Compliance
| dc.creator | Gowadia, Vaibhav | |
| dc.creator | Farkas, Csilla | |
| dc.creator | Kudo, Michiharu | |
| dc.date | 2008-09-30 | |
| dc.date.accessioned | 2026-07-07T10:06:28Z | |
| dc.date.available | 2026-07-07T10:06:28Z | |
| dc.description | Ensuring compliance of organizations to federal regulations is a growing concern. This paper presents a framework and methods to verify whether an implemented low-level security policy is compliant to a high-level security policy. Our compliance checking framework is based on organizational and security metadata to support refinement of high-level concepts to implementation specific instances. Our work uses the results of refinement calculus to express valid refinement patterns and their properties. Intuitively, a low-level security policy is compliant to a high-level security policy if there is a valid refinement path from the high-level security policy to the low-level security policy. Our model is capable of detecting violations of security policies, failures to meet obligations, and capability and modal conflicts. | |
| dc.description | 23 pages; submitted to TKDE; original submission 15 mar 2007; revised 20 jan 2008 | |
| dc.identifier | https://arxiv.org/abs/0809.5266 | |
| dc.identifier | http://arxiv.org/abs/0809.5266 | |
| dc.identifier.uri | http://salesiana.dossiersoluciones.com/handle/123456789/170336 | |
| dc.subject | Cryptography and Security | |
| dc.subject | H.1.1; H.2.0.a; I.2.2.e; I.2.4 | |
| dc.title | Checking Security Policy Compliance | |
| dc.type | text |