Achieving dynamicity in security policies enforcement using aspects |
| |
Authors: | Samiha Ayed Muhammad Sabir Idrees Nora Cuppens Frederic Cuppens |
| |
Affiliation: | 1.Institut Mines-Telecom/Telecom Bretagne,Cesson Sévigné Cedex,France |
| |
Abstract: | The dynamic configuration and evolution of large-scale heterogeneous systems has made the enforcement of security requirements one of the most critical phases throughout the system development lifecycle. In this paper, we propose a framework architecture to associate the security policies with the specification and the execution phases of applications defined for these systems. Our proposed framework is based on an aspect-oriented programming approach and on the organization-based access control model to dynamically enforce and manage the access and the usage control. The deployment of the framework modules, proposed in this paper, takes into account the changes that may occur in the security policy during the application execution. We also present the implementation as well as the evaluation of our proposition. |
| |
Keywords: | |
本文献已被 SpringerLink 等数据库收录! |