An integrity policy defines the situations when modification of information is authorized and is enforced by the security mechanisms of the system. However, in a complex application system it is possible that an integrity policy may have been incorrectly specified and, as a result, a user may be authorized to modify information that can lead to an unexpected system compromise. In this paper we outline a scalable and quantitative technique that uses constraint solving to model and analyze the effectiveness of application system integrity policies.
Citation:
Stefano Bistarelli, Simon N. Foley, "Analysis of Integrity Policies using Soft Constraints," policy, pp.77, Fourth IEEE International Workshop on Policies for Distributed Systems and Networks (POLICY'03), 2003