Abstract
With the ubiquitous deployment of large scale networks, more and more complex human interactions are supported by computer applications. This poses new challenges on the expressiveness of security policy design systems, often requiring the use of new security paradigms. In this paper we identify a restricted type of obligation which is useful to express new security policies. This type of obligation includes the following general situations: i) when two or more actions oblige each other, i.e. if one action is executed the others must also be executed and reciprocally, and ii) when an action obliges another and the obligatory action is causally dependent on the first action.
Access this chapter
Tax calculation will be finalised at checkout
Purchases are for personal use only
Preview
Unable to display preview. Download preview PDF.
Similar content being viewed by others
References
Jonscher, D.: Extending access control with duties-realized by active mechanisms. Database Security, VI: Status and Prospects. (1992) 91–112
Cuppens, F., Saurel, C.: Specifying a security policy: A case study. In: IEEE CS Computer Security Foundations Workshop (CSFW96). (1996) 123–135
Marriott, D., Sloman, M.: Implementation of a management agent for interpreting obligation policy. In: IEEE/IFIP 7th Int. W. on Distributed Systems Operations and Management, Italy (1996)
Schneider, F. B.: Enforceable security policies. The ACM Transactions on Information and System Security 3 (2000)
Gray, J., Reuter, A.: Transaction Processing: concepts and techniques. Data Management Systems. Morgan Kaufmann Publishers, Inc., San Mateo (CA), USA (1993)
Ribeiro, C., Zúquete, A., Ferreira, P., Guedes, P.: Spl: An access control language for security policies with complex constraints. In: Network and Distributed System Security Symposium (NDSS’01), San Diego, California (2001)
Denning, D.: A lattice model of secure information flow. Comm. of ACM 20 (1977)
Edwards, W. K.: Policies and roles in collaborative applications. In: ACM 1996 Conference on Computer Supported Work, New York, ACM Press (1996) 11–20
Author information
Authors and Affiliations
Editor information
Editors and Affiliations
Rights and permissions
Copyright information
© 2001 Springer-Verlag Berlin Heidelberg
About this paper
Cite this paper
Ribeiro, C., Zúquete, A., Ferreira, P. (2001). Enforcing Obligation with Security Monitors. In: Qing, S., Okamoto, T., Zhou, J. (eds) Information and Communications Security. ICICS 2001. Lecture Notes in Computer Science, vol 2229. Springer, Berlin, Heidelberg. https://doi.org/10.1007/3-540-45600-7_20
Download citation
DOI: https://doi.org/10.1007/3-540-45600-7_20
Published:
Publisher Name: Springer, Berlin, Heidelberg
Print ISBN: 978-3-540-42880-0
Online ISBN: 978-3-540-45600-1
eBook Packages: Springer Book Archive