Threat-adaptive security policy

Rajkumar Venkatesan, S. Bhattacharya · 2002

Secure systems have traditionally paid little attention to performance. This is because current secure systems apply a uniform and statically decided upon security policy to each user and do not associate an individualized level of trust with each user at run-time. This paper describes a new framework of threat and performance driven security. A threat-adaptive model which enforces a dynamic and individualized security policy mechanism, with a trust state machine capturing the different security levels is proposed. This paper discusses a threat-adaptive firewall designed for an EC application, which adaptively varies the security constraints for each user, thereby improving the system performance.

Read the paper · More papers on PaperTik