Journal of Networks, Vol 3, No 8 (2008), 55-69, Nov 2008
doi:10.4304/jnw.3.8.55-69

Heterogeneous Security Policy Validation: From Formal to Executable Specifications

Jihène Krichène, Mohamed Hamdi, Noureddine Boudriga

Abstract


This paper develops a prototyping technique for information systems security policies. Starting from the algebraic specification of a security policy, we derive an executable specification that represents a prototype of the actual policy. Executing the specification allows determining sequences of actions that lead to security policy violations. We propose a composition framework to build compound algebraic specifications. We show that the mechanism we provide to translate algebraic specifications to executable specifications preserves the composition rules, which is of utmost importance from the engineering perspective. Through accurate examples, we show how executables specifications can be used in conjunction with formal specification in the frame of the security policy engineering process.



Keywords


Algebraic specifications; executable specifications; security policy engineering

References



Full Text: PDF


Journal of Networks (JNW, ISSN 1796-2056)

Copyright @ 2006-2012 by ACADEMY PUBLISHER – All rights reserved.