| Abstract |
|
A common approach to formally describe security mechanisms is the definition of proper policies. In many contexts, a system could be considered secure and trustworthy if the policy enforced by its security administrator is trustworthy as well; within such contexts it is possible to evaluate the system security by evaluating its policy. In a previous paper we have proposed a policy-based methodology, the Reference Evaluation Methodology (REM for short), to define and evaluate the security level that a system is able to provide. In this paper we illustrate the implementation of the REM framework to automatically evaluate the security level provided by a system and we discuss a real case study on the evaluation of the Certificate Authorities involved in the EUGridPMA project.
|
Additional Information
|
Citation:
Flora Amato, Valentina Casola, Antonino Mazzeo, Valeria Vittorini,
"The REM Framework for Security Evaluation,"
ares,
pp. 1097-1103,
2008 Third International Conference on Availability, Reliability and Security,
2008
|