Threat-adaptive security policy
Rajkumar Venkatesan, S. Bhattacharya · 2002
Secure systems have traditionally paid little attention to performance. This is because current secure systems apply a uniform and statically decided upon security policy to each user and do not associate an individualized level of trust with each user at run-time. This paper describes a new framework of threat and performance driven security. A threat-adaptive model which enforces a dynamic and individualized security policy mechanism, with a trust state machine capturing the different security levels is proposed. This paper discusses a threat-adaptive firewall designed for an EC application, which adaptively varies the security constraints for each user, thereby improving the system performance.