Abstract : The premise of Quality of Security Service is that system and network management functions can be more effective if variable levels of security services and requirements can be presented to users or network tasks. In this approach, the "level of service" must be within an acceptable range, and can indicate degrees of security with respect to various aspects of assurance, mechanistic strength, administrative diligence, etc. These ranges result in additional latitude for management functions to meet overall user and system demands, as well as to balance costs and projected benefits to specific users/clients. With a broader solution space to work within the security realm, the underlying system and network management functions can adapt more gracefully to resource shortages, and thereby do a better job at maintaining requested or required levels of service in all dimensions, transforming security from a performance obstacle into an adaptive, constructive network management tool.
Abstract : Quality of Service (QoS) mechanisms can be beneficial to both the user and the overall distributed system. QoS users benefit by having reliable access to services. The distributed system whose resources are QoS managed benefits by having more predictable resource utilization and, where supported, more efficient resource allocation. We have previously examined how reliability, predictability and efficiency can be enhanced by including security as a real part of QoS, transforming security from an inflexible performance obstacle into a constructive management tool. We have termed the effects of this inclusion, "Quality of Security Service" (QoSS) 10. The motivation for the work described here is to examine specific methods for managing variability of security services, including choices offered to users, resource cost calculation, and modulation of underlying security mechanisms.
Presents our approach to handling security as a QoS dimension and discusses how variability in network security services and their associated costs can be managed in a middleware environment. We present our "quality of security service" (QoSS) concepts in terms of various security mechanisms and dynamic security policies. We also briefly describe our QoSS costing framework and demonstration, which illustrate how costs associated with network security services can be calculated and supplied to a middleware resource management system (RMS). Finally, we discuss our experiments on linking QoSS conditions to an underlying security mechanism, such as IPsec. Our aim is to demonstrate an approach through which security can be treated as a QoS dimension. We have illustrated that a security mechanism like IPsec can be modulated to provide levels of security that are in harmony with QoSS requests.
: Security requirements for a task, system or network may permit the selection of a range of underlying services or security behaviors. When a range of services is available, variant security is possible. Variant security permits the notion of Quality of Security Service (QoSS) to be introduced. This paper describes a quality of security service demonstration, specifically with respect to costing. We describe the network as having three modes: normal, impacted, and emergency. For each of these modes, the user is given three possible security levels: low, medium and high. A variety of security services contribute to the overall security of each task. Each service has two costs: an initialization cost and a run-time cost. The demonstration illustrates the costs incurred as network modes and security levels are changed. High level and detailed specifications are provided.