A Computer Network Defense Policy Refinement Method

Zhao Wei,Yanli Lv,Chunhe Xia,Yang Luo,Qing Wei
DOI: https://doi.org/10.1007/978-3-642-53959-6_12
2013-01-01
Abstract:The existing methods of policy refinement in computer network defense (CND) can only support the refinement of access control policy, but not the policies of protection, detection, response, and recovery. To solve this problem, we constructed a computer network defense policy refinement model and its formalism specification. An algorithm of defense policy refinement is designed. At last, the effectiveness of our methods was verified through one experiment cases of the composition policies with intrusion detection, vulnerabilities detection, and access control.
What problem does this paper attempt to address?