Book section Open Access

Similarity Measure for Security Policies in Service Provider Selection

Li, Yanhuang; Cuppens-Boulahia, Nora; Crom, Jean-Michel; Cuppens, Frédéric; Frey, Vincent; Ji, Xiaoshu

The interaction between different applications and services requires expressing their security properties. This is typically defined as security policies, which aim at specifying the diverse privileges of different actors. Today similarity measure for comparing security policies becomes a crucial technique in a variety of scenarios, such as finding the cloud service providers which satisfy client's security concerns. Existing approaches cover from semantic to numerical dimensions and the main work focuses mainly on XACML policies. However, few efforts have been made to extend the measure approach to multiple policy models and apply it to concrete scenarios. In this paper, we propose a generic and light-weight method to compare and evaluate security policies belonging to different models. Our technique enables client to quickly locate service providers with potentially similar policies. Comparing with other works, our approach takes policy elements' logic relationships into account and the experiment and implementation demonstrate the e ciency and accuracy of our approach.

Files (1.4 MB)
Name Size
1.4 MB Download
All versions This version
Views 7171
Downloads 146146
Data volume 206.2 MB206.2 MB
Unique views 6969
Unique downloads 142142


Cite as