论文标题
核心关闭知识基础的行动
Actions over Core-closed Knowledge Bases
论文作者
论文摘要
我们提供了有关将基于语义和知识的推理技术应用于云部署分析的新结果。特别是,将基础结构作为代码配置文件的安全性,被编码为描述逻辑知识库。我们介绍一种动作语言来建模突变行动;也就是说,通过添加,修改或删除资源来改变给定部署的结构配置的操作。我们主要关注两个问题:确定操作的执行(无论是传递给该操作的参数如何)是否会导致违反某些安全要求(静态验证)的行为,以及找到将部署到(未)所需属性的状态的动作序列的问题(计划存在和计划综合)。对于所有这些问题,我们提供定义,复杂性结果和决策程序。
We present new results on the application of semantic- and knowledge-based reasoning techniques to the analysis of cloud deployments. In particular, to the security of Infrastructure as Code configuration files, encoded as description logic knowledge bases. We introduce an action language to model mutating actions; that is, actions that change the structural configuration of a given deployment by adding, modifying, or deleting resources. We mainly focus on two problems: the problem of determining whether the execution of an action, no matter the parameters passed to it, will not cause the violation of some security requirement (static verification), and the problem of finding sequences of actions that would lead the deployment to a state where (un)desirable properties are (not) satisfied (plan existence and plan synthesis). For all these problems, we provide definitions, complexity results, and decision procedures.