13.2. Static Decision-Making Systems

The characteristic that defines this class of IRSs is that they respond to attacks defined exactly, prior to deployment, and using responses that are enumerated and completely configured. They are in generally simple to understand and deploy and work well for a large class of systems that have determinism in the kinds of workload and where the attack modes are enumerable a priori. However, they are not very effective for dynamic systems with changing workloads, new kinds of services installed, and new vulnerabilities introduced due to hardware or software changes.

13.2.1. Generic Authorization and Access Control—Application Programming Interface

Introduction

The Generic Authorization and Access Control—Application ...

Get Information Assurance now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.