Welcome!
To use the personalized features of this site, please log in or register.
If you have forgotten your username or password, we can help.
My Menu
Saved Items

Ontology-Based Policy Translation

Cataldo BasileContact Information, Antonio LioyContact Information, Salvatore ScozziContact Information and Marco ValliniContact Information

(6)  Dip. di Automatica ed Informatica, Politecnico di Torino, Torino, Italy
Abstract
Quite often attacks are enabled by mis-configurations generated by human errors. Policy-based network management has been proposed to cope with this problem: goals are expressed as high-level rules that are then translated into low-level configurations for network devices. While the concept is clear, there is a lack of tools supporting this strategy. We propose an ontology-based policy translation approach that mimics the behaviour of expert administrators, without their mistakes. We use ontologies to represent the domain knowledge and then perform reasonings (based on best practice rules) to create the configurations for network-level security controls (e.g. firewall and secure channels). If some information is missing from the ontology, the administrator is guided to provide the missing data. The configurations generated by our approach are represented in a vendor-independent format and therefore can be used with several real devices.

Contact Information Cataldo Basile
Email: cataldo.basile@polito.it

Contact Information Antonio Lioy
Email: antonio.lioy@polito.it

Contact Information Salvatore Scozzi
Email: salvatore.scozzi@gmail.com

Contact Information Marco Vallini
Email: marco.vallini@polito.it
Fulltext Preview (Small, Large)
Image of the first page of the fulltext

References secured to subscribers.



Export this chapter
Export this chapter as RIS | Text
 
Remote Address: 38.107.191.117 • Server: MPWEB34
HTTP User Agent: CCBot/1.0 (+http://www.commoncrawl.org/bot.html)