A semantic model for action-based adaptive security
Sara Sartoli, Akbar Siami Namin · 2017
This paper presents a semantic model to represent topology-based security requirements, recommend measures to address any possible security violations, and thus make the underlying systems compliant with its security requirements. The proposed action-based model is capable of adaptively adjusting the topological model of a given system in response to changes in the structure of its operational environment. The proposed framework benefits from non-monotonic reasoning to reason about possible execution paths and hence recommend actions to prevent security requirements violations. The results of our case studies show that using the proposed approach to enforce security measures, not only can we detect possible security violations caused by changes in the structure of operational environment, but also recommend actions to address possible violations.