Policy Units and Categories: Networking Models for Simplifying Security Policy Management

Madeline Van Ness, Xin Sun
{"title":"Policy Units and Categories: Networking Models for Simplifying Security Policy Management","authors":"Madeline Van Ness, Xin Sun","doi":"10.1109/IPCCC50635.2020.9391572","DOIUrl":null,"url":null,"abstract":"This paper proposes new models for simplifying policy management in enterprise networks. The application of these models to five operational networks has demonstrated their capacity for abstractly modeling network policy structures and their potential for simplifying network management tasks, which would result in reduced opportunity for human error in network management. This is useful because human error is currently a significant cause of data breaches in enterprise networks, so a reduction in human errors would be greatly beneficial to network security. Specifically, we have created two new models for abstracting policies. The policy unit model divides a network into sections, called policy units, by grouping hosts together according to similarities in the existing policy rules that are applied them. This model allows policies to be viewed and analyzed at a higher level of abstraction, which would increase the efficiency of policy management (e.g., rule changes can be applied to an entire policy unit at once). The category model groups policy units together, giving the potential for even greater efficiency. Analysis of the application of these models to five enterprise networks exposed new insight in policy management in production networks, and showed that policy management in large networks could be greatly simplified through the use of these models. This indicates the potential benefit of integrating our models in future network management systems.","PeriodicalId":226034,"journal":{"name":"2020 IEEE 39th International Performance Computing and Communications Conference (IPCCC)","volume":"28 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-11-06","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 IEEE 39th International Performance Computing and Communications Conference (IPCCC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/IPCCC50635.2020.9391572","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

This paper proposes new models for simplifying policy management in enterprise networks. The application of these models to five operational networks has demonstrated their capacity for abstractly modeling network policy structures and their potential for simplifying network management tasks, which would result in reduced opportunity for human error in network management. This is useful because human error is currently a significant cause of data breaches in enterprise networks, so a reduction in human errors would be greatly beneficial to network security. Specifically, we have created two new models for abstracting policies. The policy unit model divides a network into sections, called policy units, by grouping hosts together according to similarities in the existing policy rules that are applied them. This model allows policies to be viewed and analyzed at a higher level of abstraction, which would increase the efficiency of policy management (e.g., rule changes can be applied to an entire policy unit at once). The category model groups policy units together, giving the potential for even greater efficiency. Analysis of the application of these models to five enterprise networks exposed new insight in policy management in production networks, and showed that policy management in large networks could be greatly simplified through the use of these models. This indicates the potential benefit of integrating our models in future network management systems.
策略单元和类别:简化安全策略管理的组网模型
本文提出了简化企业网络策略管理的新模型。这些模型在五个运营网络中的应用已经证明了它们对网络策略结构进行抽象建模的能力,以及它们简化网络管理任务的潜力,这将减少网络管理中人为错误的机会。这很有用,因为人为错误目前是企业网络中数据泄露的一个重要原因,因此减少人为错误将极大地有利于网络安全。具体来说,我们创建了两个用于抽象策略的新模型。策略单元模型通过根据应用它们的现有策略规则的相似性将主机分组在一起,将网络划分为称为策略单元的部分。该模型允许在更高的抽象级别上查看和分析策略,这将提高策略管理的效率(例如,规则更改可以一次应用于整个策略单元)。类别模型将策略单元组合在一起,从而提供了更高效率的潜力。通过分析这些模型在5个企业网络中的应用,揭示了生产网络中策略管理的新见解,并表明通过使用这些模型可以大大简化大型网络中的策略管理。这表明在未来的网络管理系统中集成我们的模型的潜在好处。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信