Abstract
The tasks a system administrator must fulfill become more and more complex as information systems increase in complexity and connectivity. More specifically, the problem of the expression and update of security requirements is central. Formal models designed to express security policies have proved to be necessary since they provide non ambiguous semantics to analyze them. However, such models as RBAC or OrBAC are not used to express reaction requirements which specify the reaction policy to enforce when intrusions are detected. We present in this article an extension of the OrBAC model by defining dynamic organizations and threat contexts to enable the expression and enforcement of reaction requirements. © 2009 Springer Berlin Heidelberg.
Cite
CITATION STYLE
Autrel, F., Cuppens-Boulahia, N., & Cuppens, F. (2009). Reaction policy model based on dynamic organizations and threat context. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 5645 LNCS, pp. 49–64). https://doi.org/10.1007/978-3-642-03007-9_4
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.