论文部分内容阅读
为保证特定安全域的各类安全设备在基于策略的管理体系中协同工作,避免策略执行时的矛盾与冲突,研究了安全策略的验证方法。按照子网划分安全域,并基于状态机模型描述安全域中设备状态在安全事件触发条件下的变迁形式,定义了安全策略。针对安全策略知识库的构建及其正确性、完整性、一致性、冗余性和可执行性的验证问题,提出了基于状态有向图深度优先遍历的策略验证方法。算法的复杂度分析和实验结果表明了策略验证方法具有理想的执行效率。
In order to ensure that all kinds of security devices in a specific security domain work together in a policy-based management system to avoid conflicts and conflicts in policy enforcement, the verification methods of security policies are studied. The security domain is divided according to the subnet, and the security policy is defined based on the state machine model to describe the change of the device state in the security domain under the trigger condition of the security event. In view of the construction of the security strategy knowledge base and its verification of correctness, completeness, consistency, redundancy and enforceability, a policy validation method based on state-directed graph depth-first traversal is proposed. The complexity analysis of the algorithm and experimental results show that the method of policy verification has an ideal execution efficiency.