Comparative Study on Network Policy Specification Languages
摘要
Implementing appropriate network policies in enterprise networks has become more difficult due to complex organizational needs involving a wide array of computing and cybersecurity devices. These policies cover various aspects such as resource health monitoring, configuration management, dynamic access control, and safeguarding against new vulnerabilities and associated threats. The challenge is compounded by constant changes in configurations and network structures, inter-dependencies among device configurations, and the decentralized nature of policy implementation across networks. Furthermore, network service dependencies may result in undiscovered entry points that potentially expose organizational resources to attackers. To effectively manage network policies, it is essential to articulate these complex policies in a language that can be easily understood by human administrators and policymakers, while also being enforceable on network components. In a device-independent information model, the language must be able to represent network elements, their attributes, functions, and relationships. To be runnable, the policy specification must be free of conflicts and match the device’s capabilities. In this paper, we present a comparative study on the effectiveness of the state-of-art policy specification languages in enterprise networks with extensive case studies. The study helps the administrators and policymakers to choose appropriate policy specification language depending on the complexity of the implementation scenario.