FirewallWizards
[Top] [All Lists]

[fw-wiz] Security policy language

To: firewall-wizards@listserv.icsalabs.com
Subject: [fw-wiz] Security policy language
From: Marco Cremonini <cremonini@dti.unimi.it>
Date: Wed, 24 Jan 2007 09:51:13 +0100
Delivered-to: sp-com-lists@consult.net
Delivered-to: fwwizards-list2@consult.net
Delivered-to: firewall-wizards@listserv.icsalabs.com
List-archive: <https://listserv.icsalabs.com/pipermail/firewall-wizards>
List-help: <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=help>
List-id: Firewall Wizards Security Mailing List <firewall-wizards.listserv.icsalabs.com>
List-post: <mailto:firewall-wizards@listserv.icsalabs.com>
List-subscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=subscribe>
List-unsubscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=unsubscribe>
Reply-to: Firewall Wizards Security Mailing List <firewall-wizards@listserv.icsalabs.com>
Sender: firewall-wizards-bounces@listserv.icsalabs.com
Hi all,
     I would like to ask you a suggestion for a project we are  
developing.
The project aims to automate some monitoring functionality with  
firewall policy management (just iptables, at present).
The problem is: We would like to implement/adopt a high-level  
specification language for the definition of a security policy,  
something that should let to specify the policy at organizational  
level. Such a policy should then  be translated into specific fw rules.

I'm puzzled because it's not a new problem, but I can't find good  
references. Several standards, especially in the XML-Web Services  
area, have been proposed by W3C, OASIS etc., to define security  
policies, but to me they seem quite useless in our case since I can't  
see how and why Web Services should be integrated in this context.

I've found out that Mitre has a language, Oval (http://oval.mitre.org/ 
index.html), which could be considered, although more focused on  
vulnerability and assessment.

Otherwise, many have designed ad-hoc languages (I guess, just using  
GNU Flex&Bison or the like for their definition).

Before going for yet-another-adhoc-language I just want to ask if  
anybody knows a good standard or reference specification language.

Thank you.
Marco

===================================
Marco Cremonini
cremonini@dti.unimi.it
Dept. of Information Technology
University of Milan
Via Bramante 65 - 26013 Crema (CR), Italy
===================================



_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

<Prev in Thread] Current Thread [Next in Thread>