A generic data flow security model

El Khoury Hicham, Romain Laborde, François Barrère, Abdelmalek Benzekri, Maroun Chamoun · 2011

Network security policy enforcement consists in configuring heterogeneous security mechanisms (IPsec gateways, ACLs on routers, stateful firewalls, proxies, etc) that are available in a given network environment. The complexity of this task resides in the number, the nature, and the interdependence of the mechanisms. We propose in this paper a formal data flow model focused on detecting multi-layer inconsistencies between security mechanisms. This model is independent from specific security mechanisms to admit the security technology diversity and evolution.

Read the paper · More papers on PaperTik