Abstract
Managing the security of complex cloud and networked computing environments requires crafting security policy-ranging from natural-language text to highly-structured configuration rules, sometimes multi-layered-specifying correct system behavior in an adversarial environment. Since environments change and evolve, managing security requires managing evolution of policies, which adds another layer, the change log. However, evolution increases complexity, and the more complex a policy, the harder it is to manage and update, and the more prone it is to be incorrect. This paper proposes hierarchical change mining, drawing upon the tools of software engineering and data mining, to help practitioners introduce fewer errors when they update policy. We discuss our approach and initial findings based on two longitudinal real-world datasets: low-level router configurations from Dartmouth College and high-level Public Key Infrastructure (PKI) certificate policies from the International Grid Trust Federation (IGTF).
| Original language | English |
|---|---|
| State | Published - 2011 |
| Event | 1st USENIX Workshop on Hot Topics in Management of Internet, Cloud, and Enterprise Networks and Services, Hot-ICE 2011 held in conjunction with the 8th USENIX Symposium on Networked Systems Design and Implementation, NSDI 2011 - Boston, United States Duration: Mar 29 2011 → Mar 29 2011 |
Conference
| Conference | 1st USENIX Workshop on Hot Topics in Management of Internet, Cloud, and Enterprise Networks and Services, Hot-ICE 2011 held in conjunction with the 8th USENIX Symposium on Networked Systems Design and Implementation, NSDI 2011 |
|---|---|
| Country/Territory | United States |
| City | Boston |
| Period | 03/29/11 → 03/29/11 |
Fingerprint
Dive into the research topics of 'Using hierarchal change mining to manage network security policy evolution'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver