Saved in:
Bibliographic Details
Main Authors: Basile, Cataldo, Gatti, Gabriele, Settanni, Francesco
Format: Preprint
Published: 2024
Subjects:
Online Access:https://arxiv.org/abs/2405.03544
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915097922764800
author Basile, Cataldo
Gatti, Gabriele
Settanni, Francesco
author_facet Basile, Cataldo
Gatti, Gabriele
Settanni, Francesco
contents Enforcing security requirements in networked information systems relies on security controls to mitigate the risks from increasingly dangerous threats. Configuring security controls is challenging; even nowadays, administrators must perform it without adequate tool support. Hence, this process is plagued by errors that translate to insecure postures, security incidents, and a lack of promptness in answering threats. This paper presents the Security Capability Model (SCM), a formal model that abstracts the features that security controls offer for enforcing security policies, which includes an Information Model that depicts the basic concepts related to rules (i.e., conditions, actions, events) and policies (i.e., conditions' evaluation, resolution strategies, default actions), and a Data Model that covers the capabilities needed to describe different types of filtering and channel protection controls. Following state-of-the-art design patterns, the model allows for generating abstract versions of the security controls' languages and a model-driven approach for translating abstract policies into device-specific configuration settings. By validating its effectiveness in real-world scenarios, we show that SCM enables the automation of different and complex security tasks, i.e., accurate and granular security control comparison, policy refinement, and incident response. Lastly, we present opportunities for extensions and integration with other frameworks and models.
format Preprint
id arxiv_https___arxiv_org_abs_2405_03544
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle A Formal Model of Security Controls' Capabilities and Its Applications to Policy Refinement and Incident Management
Basile, Cataldo
Gatti, Gabriele
Settanni, Francesco
Cryptography and Security
Enforcing security requirements in networked information systems relies on security controls to mitigate the risks from increasingly dangerous threats. Configuring security controls is challenging; even nowadays, administrators must perform it without adequate tool support. Hence, this process is plagued by errors that translate to insecure postures, security incidents, and a lack of promptness in answering threats. This paper presents the Security Capability Model (SCM), a formal model that abstracts the features that security controls offer for enforcing security policies, which includes an Information Model that depicts the basic concepts related to rules (i.e., conditions, actions, events) and policies (i.e., conditions' evaluation, resolution strategies, default actions), and a Data Model that covers the capabilities needed to describe different types of filtering and channel protection controls. Following state-of-the-art design patterns, the model allows for generating abstract versions of the security controls' languages and a model-driven approach for translating abstract policies into device-specific configuration settings. By validating its effectiveness in real-world scenarios, we show that SCM enables the automation of different and complex security tasks, i.e., accurate and granular security control comparison, policy refinement, and incident response. Lastly, we present opportunities for extensions and integration with other frameworks and models.
title A Formal Model of Security Controls' Capabilities and Its Applications to Policy Refinement and Incident Management
topic Cryptography and Security
url https://arxiv.org/abs/2405.03544