Management of heterogeneous security access control configuration using an ontology engineering approach

William M. Fitzgerald, Simon N. Foley · 2010

Management of heterogeneous enterprise security mechanisms is complex and requires a security administrator to have deep knowledge of each security mechanism's configuration. Effective configuration may be hampered by poor understanding and/or management of the enterprise security policy which, in turn, may unnecessarily expose the enterprise to known threats. This paper argues that knowledge about detailed security configuration, enterprise-level security requirements including best practice recommendations and their relationships can be modelled, queried and reasoned over within an ontology-based framework. A threat-based approach is taken to structure this knowledge. The management of XMPP application-level and firewall-level access control configuration is investigated.

Read the paper · More papers on PaperTik