Advanced hacker techniques make the effective defense at the network security perimeters impossible. Many security solutions are proposed by researchers and practitioners in recent years, most of them focus on how to enhance the functionality and capability of security modules, but few of them emphasize on the assurance assessments of security modules. Security assurance intends to provide a degree of confidence instead of a true measure of how secure the system is. Security assurance should be measured and controlled in the process of security management life cycle. In this paper, we propose a security model, Object Association Binding (OAB), to unify the access control policies and to provide an objective assessment for the confidence level of network security assurance. Based on the design principles of OAB, its prototype called Network Security Policy Assistant (NSPA) is implemented.
Citation:
Bo-Chao Cheng, Huan Chen, Ryh-Yuh Tseng, "A Theoretical Security Model for Access Control and Security Assurance," ias, pp.137-142, 2007 The Third International Symposium on Information Assurance and Security, 2007