<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//TaxonX//DTD Taxonomic Treatment Publishing DTD v0 20100105//EN" "../../nlm/tax-treatment-NS0.dtd">
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:tp="http://www.plazi.org/taxpub" article-type="research-article" dtd-version="3.0" xml:lang="en">
  <front>
    <journal-meta>
      <journal-id journal-id-type="publisher-id">109</journal-id>
      <journal-id journal-id-type="index">urn:lsid:arphahub.com:pub:3dc5f44e-8666-58db-bc76-a455210e8891</journal-id>
      <journal-title-group>
        <journal-title xml:lang="en">JUCS - Journal of Universal Computer Science</journal-title>
        <abbrev-journal-title xml:lang="en">jucs</abbrev-journal-title>
      </journal-title-group>
      <issn pub-type="ppub">0948-695X</issn>
      <issn pub-type="epub">0948-6968</issn>
      <publisher>
        <publisher-name>Journal of Universal Computer Science</publisher-name>
      </publisher>
    </journal-meta>
    <article-meta>
      <article-id pub-id-type="doi">10.3217/jucs-011-01-0150</article-id>
      <article-id pub-id-type="publisher-id">28345</article-id>
      <article-categories>
        <subj-group subj-group-type="heading">
          <subject>Research Article</subject>
        </subj-group>
        <subj-group subj-group-type="scientific_subject">
          <subject>K.4.2 - Social Issues</subject>
          <subject>K.6.5 - Security and Protection</subject>
        </subj-group>
      </article-categories>
      <title-group>
        <article-title>A Reference Model for Security Level Evaluation: Policy and Fuzzy Techniques</article-title>
      </title-group>
      <contrib-group content-type="authors">
        <contrib contrib-type="author" corresp="yes">
          <name name-style="western">
            <surname>Casola</surname>
            <given-names>Valentina</given-names>
          </name>
          <email xlink:type="simple">valentina.casola@unina2.it</email>
          <xref ref-type="aff" rid="A1">1</xref>
        </contrib>
        <contrib contrib-type="author" corresp="no">
          <name name-style="western">
            <surname>Preziosi</surname>
            <given-names>Rosa</given-names>
          </name>
          <xref ref-type="aff" rid="A2">2</xref>
        </contrib>
        <contrib contrib-type="author" corresp="no">
          <name name-style="western">
            <surname>Rak</surname>
            <given-names>Massimiliano</given-names>
          </name>
          <xref ref-type="aff" rid="A1">1</xref>
        </contrib>
      </contrib-group>
      <aff id="A1">
        <label>1</label>
        <addr-line content-type="verbatim">Dipartimento di Ingegneria dell'Informazione, Second University of Naples, , Italy</addr-line>
        <institution>Dipartimento di Ingegneria dell'Informazione, Second University of Naples</institution>
        <country>Italy</country>
      </aff>
      <aff id="A2">
        <label>2</label>
        <addr-line content-type="verbatim">RCOST, Department of Engineering, University of Sannio, , Italy</addr-line>
        <institution>RCOST, Department of Engineering, University of Sannio</institution>
        <country>Italy</country>
      </aff>
      <author-notes>
        <fn fn-type="corresp">
          <p>Corresponding author: Valentina Casola (<email xlink:type="simple">valentina.casola@unina2.it</email>).</p>
        </fn>
        <fn fn-type="edited-by">
          <p>Academic editor: </p>
        </fn>
      </author-notes>
      <pub-date pub-type="collection">
        <year>2005</year>
      </pub-date>
      <pub-date pub-type="epub">
        <day>28</day>
        <month>01</month>
        <year>2005</year>
      </pub-date>
      <volume>11</volume>
      <issue>1</issue>
      <fpage>150</fpage>
      <lpage>174</lpage>
      <uri content-type="arpha" xlink:href="http://openbiodiv.net/E3819E80-FB66-5707-AA3F-6F321CBD3793">E3819E80-FB66-5707-AA3F-6F321CBD3793</uri>
      <uri content-type="zenodo_dep_id" xlink:href="https://zenodo.org/record/6996691">6996691</uri>
      <permissions>
        <copyright-statement>Valentina Casola, Rosa Preziosi, Massimiliano Rak</copyright-statement>
        <license license-type="creative-commons-attribution" xlink:href="" xlink:type="simple">
          <license-p>This article is freely available under the J.UCS Open Content License.</license-p>
        </license>
      </permissions>
      <abstract>
        <label>Abstract</label>
        <p>In a world made of interconnected systems which manage huge amounts of confidential and shared data, security plays a significant role. Policies are the means by which security rules are defined and enforced. The ability to evaluate policies is becoming more and more relevant, especially when referred to the cooperation of services belonging to untrusted domains. We have focused our attention on Public Key Infrastructures (PKIs), at the state of the art security policies evaluation is manually performed by technical and organizational people coming from the domains that need to interoperate. However, policy evaluation must face uncertainties derived from different perspectives, verbal judgments and lack of information. Fuzzy techniques and uncertainty reasoning can provide a meaningful way for dealing with these issues. In this paper we propose a fuzzy technique to characterize a policy and to define a Reference Evaluation Model representing different security levels against which we are able to evaluate and compare policies. The comparison takes into account not only minimal system needs but evaluator s severity, too, furthermore it gives clear information regarding policy weakness that could be used to help security administrators to better enforce rules. Finally we present a case study which evaluates the security level of a legally recognized policy.</p>
      </abstract>
    </article-meta>
  </front>
</article>
