Skip to main content
Back to USENIX
  • Conferences
  • Students
Sign in

USENIX Conference Policies

  • Event Code of Conduct
  • Conference Network Policy
  • Statement on Environmental Responsibility Policy

A Comparison of Methods for Implementing Adaptive Security Policies

Michael Carney and Brian Loe, Secure Computing Corporation

The security policies for computing resources must match the security policies of the organizations that use them; therefore, computer security policies must be adaptive to meet the changing security environment of their user-base. This paper presents four methods for implementing adaptive security policies for architectures which separate the definition of the policy in a Security Server from the enforcement which is done by the kernel. The four methods discussed include

  • reloading a new security database for the Security Server,
  • expanding the state and security database of the Security Server to include more than one mode of operation,
  • implementing another Security Server and handing off control for security computations, and
  • implementing multiple, concurrent Security Servers each controlling a subset of processes.

Each of these methods comes with a set of trade-offs: policy flexibility, functional flexibility, security, reliability, and performance. This paper evaluates each of the implementations with respect to each of these criteria. Although the methods described in this paper were implemented for the Distributed Trusted Operating System (DTOS) prototype, this paper describes general research, and the conclusions drawn from this work need not be limited to that development platform.

Michael Carney, Secure Computing Corporation

Brian Loe, Secure Computing Corporation

BibTeX
@inproceedings {261388,
author = {Michael Carney and Brian Loe},
title = {A Comparison of Methods for Implementing Adaptive Security Policies},
booktitle = {7th USENIX Security Symposium (USENIX Security 98)},
year = {1998},
address = {San Antonio, TX},
url = {https://www.usenix.org/conference/7th-usenix-security-symposium/comparison-methods-implementing-adaptive-security-policies},
publisher = {USENIX Association},
month = jan
}
Download

Links

Paper: 
http://usenix.org/publications/library/proceedings/sec98/full_papers/loe/loe.pdf
Paper (HTML): 
http://usenix.org/publications/library/proceedings/sec98/full_papers/loe/loe_html/loe.html
  • Log in or register to post comments

© USENIX
EIN 13-3055038

  • Privacy Policy
  • Contact Us